Splunk Enterprise Security

Why is there an increase in security notables event count?

umesh
Path Finder

Hi Team,

 

I have created a notable in the Splunk ES and i received a notable and i analyzed the notable and i can see 130 events in the raw logs. But after sometime if i analyse the same notable i can see that there is increase in the  count of events . Can i know what the issue is regarding the increase in the event count.

Thanks & Regards,

Umesh

Tags (2)
0 Karma

umesh
Path Finder

@gcusello  can you please help on this. when i click on the contributing events in notable alert it is showing count of 59 events and aftersometime when i analyse the same notable contributing events link  the event count is getting increased. Please i explain the reason why it is happening 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @umesh,

it should be analyzed in your installation, but probably because the search has latest=now, so in the meantime other events arrived.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...