- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I make an ES Incident Review copy of my Notables?
kanyewestnewmer
New Member
04-01-2023
01:09 AM
How can we halt duplicate notables from being created on the Enterprise security Incident Review page for the same event id? Do any parameters need to be changed?
Ranging from earliest to latest: -70M to -10M
every 35 minutes on a cron plan
All correlation inquiries experience it.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
scelikok

SplunkTrust
04-03-2023
04:21 AM
Hi @kanyewestnewmer,
Since you are running the exact correlation twice in the same time range, it is normal having duplicate notables. You should use 60 minutes as a cron plan or throttling on the event_id field.
If this reply helps you an upvote and "Accept as Solution" is appreciated.
