Splunk Enterprise Security

ES app Incident review can not see any notable event

mchang_splunk
Splunk Employee
Splunk Employee

I can find correlation searches created notable events:

01-20-2019 00:01:29.782 -0500 INFO  sendmodalert - Invoking modular alert action=notable for search="Asset - Asset Ownership Unspecified - Rule" sid="scheduler__admin_U0EtSWRlbnRpdHlNYW5hZ2VtZW50__RMD5adc793953e142031_at_1547960400_9000" in app="SA-IdentityManagement" owner="admin" type="saved"
01-20-2019 04:04:14.870 -0500 INFO  sendmodalert - Invoking modular alert action=notable for search="Access - Account Deleted - Rule" sid="rt_scheduler__admin_U0EtQWNjZXNzUHJvdGVjdGlvbg__RMD5eaf4137ed4b67244_at_1547974933_12088.1" in app="SA-AccessProtection" owner="admin" type="saved"

By searching "index=notable", I can see notable events but nothing found in incident review dashboard.

0 Karma
1 Solution

mchang_splunk
Splunk Employee
Splunk Employee

You might have suppressed your notable events.

Please go ES app -> Configure -> Incident Management -> "Notable Event Suppressions"
Check if any suppressions set.

Here is the answer you can refer to:
https://answers.splunk.com/answers/73722/is-there-an-easy-way-to-close-out-150k-incident-events.html

View solution in original post

0 Karma

mchang_splunk
Splunk Employee
Splunk Employee

You might have suppressed your notable events.

Please go ES app -> Configure -> Incident Management -> "Notable Event Suppressions"
Check if any suppressions set.

Here is the answer you can refer to:
https://answers.splunk.com/answers/73722/is-there-an-easy-way-to-close-out-150k-incident-events.html

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...