Splunk Enterprise Security

Hiding statuses in "Edit event" box in splunk ES

rishav
Explorer

I have added some custom notable event statues say a , b , c.

I have modified the transition rules for "new" status such that ess_analyst  role should not  be able to make transition from new to a ,  b and c statuses.

 But the issue is while  status a and b are hidden from the "Edit events" box, the c is not .

Though the transition to status c is still disabled for analyst.

 

the id for a = 14, b =15 and c is 10.

Please help me understand why I see this  behaviour.

 

 

Labels (1)
1 Solution

rishav
Explorer

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

View solution in original post

rishav
Explorer

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...