Environment: Splunk Enterprise Security 8.5.1 (on-prem) I have "Hide findings" turned on under Configure → Findings and investigations → Analyst queue settings. Per the UI tooltip, this should hide findings from the analyst queue when they're included in an investigation or finding group: "Hide findings from the analyst queue when it is included in an investigation or finding group. Note: Hidden findings will be nested within investigations or finding groups." However, when I have a finding-based detection (FBD) that groups multiple findings into a finding group, the individual child findings still show up as separate top-level rows in the analyst queue in addition to being nested under the finding group — see screenshot attached. This defeats the purpose of the setting. Screenshot shows: A finding group ("xxx - fbd - test") with 4 nested findings ("xxx - finding test - windows") The same 4 findings also appearing as standalone rows below, un-hidden We were previously on ES 8.3 and did not see this behavior — findings that were part of a finding group were correctly suppressed from the top-level queue. This regression appeared after upgrading to 8.5.1. I suspect this may be related to the known issue SECHELP-448 (ad-hoc searches launched from the ES app running under the Mission Control app context instead of the ES app context post-8.4/8.5 upgrade, causing app-scoped lookups/macros to silently return incomplete results). If Hide findings relies on an app-scoped lookup to check finding-group membership, that would explain why it's silently failing here. Has anyone else run into this on 8.4/8.5? Is there a known workaround, or is this expected to be addressed as part of SECHELP-448? Happy to provide diagnostic logs, btool output, or further screenshots if useful.
... View more