I have a notable event seen in Splunk Enterprise Security's Security Posture dashboard.
I have reviewed it and determined it to be a false positive.
I want to remove it from view on the Security Posture dashboard.
Is there any way to do this?
Click the Edit-> Edit Panels in the Security Posture Dashboard.
Under the Top Notable Events, click the search report and select Notable-Top Events and select Open in Search. Add
status_group="New" to this search:
| `es_notable_events` | search timeDiff_type=current status_group="New" | stats sparkline(sum(count),30m) as sparkline,sum(count) as count by rule_name | sort 100 - count
Click Save, Save Dashboard. click Done
The Security Posture Dashboard will only show New Notable events
In the current form, there is no easy way to delete a notable event. The basic idea here is that event your false positives, you want to categorize. So you could create a new class for false positives and classify these notables into this.
If you're really looking to delete the events, you'll need to look at the
notables macros, and where they are pulling the data from. In the latest versions of ES, notables are stored between KVStore, lookup files, and summary indexes..
I don't want to make all the alerts false positives. Just the specific event that was investigated.
Would grouping them into a new class push all like events there? Or just that event?
Also, deleting the events, as you mentioned above, would delete all the notable events of the same kind; correct?