Hello, I'm interested in minimizing the amount of noise generated by notables in one of my customer's environments, which has produced 3500 notables in the past 15 days. Is it necessary to review all 3500 notables to filter out common events?
I suspect one or more of the following apply.
1) The customer activated too many correlation searches. They should disable the CSs for conditions they aren't interested in.
2) The CSs they do care about have thresholds that are too low. The CSs should be modified so they are less sensitive.
3) The CSs are running too frequently. Change their schedules so they run less often.
4) The CSs are not throttling. Throttling prevents repeated notables for a condition that continues to occur and allows the analyst time to remediate the condition before another notable arrives. See https://docs.splunk.com/Documentation/ES/7.1.1/Admin/Configurecorrelationsearches#Throttle_the_numbe...