Splunk Enterprise Security

Duplicate Notable Events

warsaw
Loves-to-Learn Lots

On Splunk 7.3.1.1 and now suddenly out of nowhere this issue popped up, the notable alerts are being duplicated for almost 80% of my co relation searches, when i check the raw events for those duplicates they're exactly same, so no question of duplicity of actual logs, but only for the notable alerts that are generated in Incident Review Dashboard of Enterprise Security.

Does anyone faced this issue or have resolved it?

@woodcock 

0 Karma

sbaileigh
Observer

Do you have a screenshot? Are they created on the notable index at the same time? For some of the searches, what are the triggered actions configured? Any way a series of daisy chained triggered actions leads to another notable being created?

0 Karma

fmohmand
Observer

Facing same issue  since 3 weeks.

0 Karma

Vijeta
Influencer

Seeing the same issue, any solution?

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...