Splunk Enterprise Security

Why is notable suppression not working?

kkrises
Path Finder

Hello Splunkers,

I configured a new Notable suppression in ES for a repeated notable based on source IP. I could see the suppression entry is created under eventtypes, but the notable is still coming to Incident Review console.

I suspect issue with my Search configuration under the suppression settings.

My search config is like below :

index=network dest_port IN(389,636) src_ip=10.x.x.x 

This was to suppress notables triggering for my recent LDAP traffic search. Thank you.

Tags (1)
0 Karma
1 Solution

kkrises
Path Finder

@VatsalJagani - Thanks for the help. Querying the index notable worked in this case and have to adjust the fields as below : 

index=notable src_ip="10.x.x.x" search_name="ESCU - Detect Outbound LDAP Traffic - Rule". This worked and notables are not coming in now.

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@kkrises - Your search should look something like this:

`get_notable_index` dest_port IN(389,636) src_ip=10.x.x.x

(You need to run on notable index, not on network index)

Make sure your correlation search is generating dest_port and src_ip as a result.

 

I hope this helps!!!

kkrises
Path Finder

@VatsalJagani - Thanks for the help. Querying the index notable worked in this case and have to adjust the fields as below : 

index=notable src_ip="10.x.x.x" search_name="ESCU - Detect Outbound LDAP Traffic - Rule". This worked and notables are not coming in now.

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@kkrises - Please share your ES suppression config so we can check what's wrong.

0 Karma

kkrises
Path Finder

This is my search string for ES suppression config.

index=network dest_port IN(389,636) src_ip=10.x.x.x 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...