Splunk ITSI

How to suppress Notable Events in ITSI?

ManjunathN
Engager

Hi,

 

How to suppress the notable events in Splunk itsi ?

And when an episode breaks will the related notable events gets cleared? 

And when an new episode gets created the related notable events count will be a fresh count from the time of episode creation or it will be a accumulated from the previous count. Please clarify. Thanks!

Labels (1)
0 Karma

lperini_splunk
Splunk Employee
Splunk Employee

How to suppress the notable events in Splunk itsi ?

Configuration > Correlation Searches > Open the Correlation Search > Advanced Options
For more information:

https://docs.splunk.com/Documentation/ITSI/4.14.0/EA/ConfigCS#Advanced_Options

And when an episode breaks will the related notable events gets cleared? 

No, the notables are not cleared. What happens is: a new episode is created, and the new notables are going to this new episode. So the notables that came before this "break" are kept in the previous episode.

https://docs.splunk.com/Documentation/ITSI/4.14.0/EA/FilteringCriteria#Break_episode

when an new episode gets created the related notable events count will be a fresh count from the time of episode creation or it will be a accumulated from the previous count. 

It will be a fresh count from the time of the episode creation.

 

 

0 Karma
Get Updates on the Splunk Community!

Meet Duke Cyberwalker | A hero’s journey with Splunk

We like to say, the lightsaber is to Luke as Splunk is to Duke. Curious yet? Then read Eric Fusilero’s latest ...

The Future of Splunk Search is Here - See What’s New!

We’re excited to introduce two powerful new search features, now generally available for Splunk Cloud Platform ...

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...