Hello,
I have SH cluster with Enterprise Security deployed (Splunk version 8.0.4.1, Ent. Security 6.2.0). I created Notable event suppression for particular Notable event (using Incident Review dashboard). I set Expiration time for this suppression. Everything worked as expected. But then I found that NE suppression is still active, even after expiration time - no NE visible in Incident Review dashboard. (But there were Notable Events in notable index all the time, as expected). In other words, Splunk simply ignored Expiration time of NE suppression and behave as NE suppression was set without Expiration time. Notable Events became visible in Incident Review after NE suppression was manually disabled and from this point everything work as expected.
There are few other NE suppressions and all works as expected.
I examined Splunk logs, but I cannot see nothing suspicious. I am not able to reproduce this behavior again by any way.
Is here someone with similar experience? Could someone give me hint what I should look for to find root cause of this behavior?
Best regards
Lukas