Splunk Enterprise Security

Hiding statuses in "Edit event" box in splunk ES

rishav
Explorer

I have added some custom notable event statues say a , b , c.

I have modified the transition rules for "new" status such that ess_analyst  role should not  be able to make transition from new to a ,  b and c statuses.

 But the issue is while  status a and b are hidden from the "Edit events" box, the c is not .

Though the transition to status c is still disabled for analyst.

 

the id for a = 14, b =15 and c is 10.

Please help me understand why I see this  behaviour.

 

 

Labels (1)
1 Solution

rishav
Explorer

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

View solution in original post

rishav
Explorer

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...