Splunk Enterprise Security

Hiding statuses in "Edit event" box in splunk ES

rishav
Engager

I have added some custom notable event statues say a , b , c.

I have modified the transition rules for "new" status such that ess_analyst  role should not  be able to make transition from new to a ,  b and c statuses.

 But the issue is while  status a and b are hidden from the "Edit events" box, the c is not .

Though the transition to status c is still disabled for analyst.

 

the id for a = 14, b =15 and c is 10.

Please help me understand why I see this  behaviour.

 

 

Labels (1)
1 Solution

rishav
Engager

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

View solution in original post

rishav
Engager

So I found the answer myself,  to make a status hidden in "Edit Event " box,  transition to it has to be disabled from all the statuses present in the ES.

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>