Splunk ITSI

How to suppress Notable Events in ITSI?

ManjunathN
Engager

Hi,

 

How to suppress the notable events in Splunk itsi ?

And when an episode breaks will the related notable events gets cleared? 

And when an new episode gets created the related notable events count will be a fresh count from the time of episode creation or it will be a accumulated from the previous count. Please clarify. Thanks!

Labels (1)
0 Karma

lperini_splunk
Splunk Employee
Splunk Employee

How to suppress the notable events in Splunk itsi ?

Configuration > Correlation Searches > Open the Correlation Search > Advanced Options
For more information:

https://docs.splunk.com/Documentation/ITSI/4.14.0/EA/ConfigCS#Advanced_Options

And when an episode breaks will the related notable events gets cleared? 

No, the notables are not cleared. What happens is: a new episode is created, and the new notables are going to this new episode. So the notables that came before this "break" are kept in the previous episode.

https://docs.splunk.com/Documentation/ITSI/4.14.0/EA/FilteringCriteria#Break_episode

when an new episode gets created the related notable events count will be a fresh count from the time of episode creation or it will be a accumulated from the previous count. 

It will be a fresh count from the time of the episode creation.

 

 

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...