Splunk Enterprise Security

delete top notable event from the "Top Notable Events" panel in ES Security Posture page

soumyasaha25
Contributor

I have disabled a few of the Correlation searches and would like to delete them from the "Top Notable Events" panel in ES Security Posture page.

There is some recommendation on this but the answers are quite old, is there any good way to achieve this with min impact as i understand that i would have to modify the KVstore lookup for it.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!