Splunk Enterprise Security

Notable event suppression active even after expiration time

lukasmecir
Path Finder

Hello,

I have SH cluster with Enterprise Security deployed (Splunk version 8.0.4.1, Ent. Security 6.2.0). I created Notable event suppression for particular Notable event (using Incident Review dashboard). I set Expiration time for this suppression. Everything worked as expected. But then I found that NE suppression is still active, even after expiration time - no NE visible in Incident Review dashboard.  (But there were Notable Events  in notable index all the time, as expected). In other words, Splunk simply ignored Expiration time of NE suppression and behave as NE suppression was set without Expiration time. Notable Events became visible in Incident Review after NE suppression was manually disabled and from this point everything work as expected.

There are few other NE suppressions and all works as expected.

I examined Splunk logs, but I cannot see nothing suspicious. I am not able to reproduce this behavior again by any way.

Is here someone with similar experience? Could someone give me hint what I should look for to find root cause of this behavior?

Best regards

Lukas

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...