- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to reduce notable events that correlation search has generating?
balu1211
Path Finder
01-05-2023
10:48 AM
Hi,
I have created an advance threat protection incidents Correlation Search which is generating notable events how I can make it to reduce the notables which it is generating.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
lblystone

Splunk Employee
01-06-2023
09:35 AM
If you are getting duplicate alerts for the same ATP incidents, look into throttling the results based on the same field values.
Check out this page for more information. https://docs.splunk.com/Documentation/ES/7.0.2/Tutorials/ScheduleCorrelationSearch#:~:text=Set%20up%...
