Splunk Dev

Suppress Notable Event during certain time slot

jacqu3sy
Path Finder

Is it possible to suppress notable events in Enterprise Security during a specific time window?

i.e. when a server gets rebooted during a specific maintenance window that is the same time every day?

Tags (1)

Unister
Explorer

The python variable DEFAULT_DROPEXP contains fieldnames to delete when creating a notable event. As it contains date_*, you cannot directly use the date in a notable event suppression. But if you add

| rename date_hour as orig_date_hour, date_minute as orig_date_minute, date_wday as orig_date_wday

to the end of your correlation search, you can use the renamed fields in the notable event suppression:

`get_notable_index` orig_host=YOURHOST orig_date_hour=6 orig_date_minute>=25
0 Karma

jbjerke_splunk
Splunk Employee
Splunk Employee
0 Karma

Unister
Explorer

the linked page only shows how to set an Expiration Time. The author wants to suppress eventX between 03:00 and 03:59 every day. I had done this with date_hour in my event_suppression.

On a new installation this does not work anymore because the field date_hour is not added to notable events anymore...

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...