Splunk Enterprise Security

Hiding statuses in "Edit event" box in splunk ES

rishav
Explorer

I have added some custom notable event statues say a , b , c.

I have modified the transition rules for "new" status such that ess_analyst  role should not  be able to make transition from new to a ,  b and c statuses.

 But the issue is while  status a and b are hidden from the "Edit events" box, the c is not .

Though the transition to status c is still disabled for analyst.

 

the id for a = 14, b =15 and c is 10.

Please help me understand why I see this  behaviour.

 

 

Labels (1)
1 Solution

rishav
Explorer

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

View solution in original post

rishav
Explorer

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...