Splunk Enterprise Security

Notable event suppression active even after expiration time

lukasmecir
Path Finder

Hello,

I have SH cluster with Enterprise Security deployed (Splunk version 8.0.4.1, Ent. Security 6.2.0). I created Notable event suppression for particular Notable event (using Incident Review dashboard). I set Expiration time for this suppression. Everything worked as expected. But then I found that NE suppression is still active, even after expiration time - no NE visible in Incident Review dashboard.  (But there were Notable Events  in notable index all the time, as expected). In other words, Splunk simply ignored Expiration time of NE suppression and behave as NE suppression was set without Expiration time. Notable Events became visible in Incident Review after NE suppression was manually disabled and from this point everything work as expected.

There are few other NE suppressions and all works as expected.

I examined Splunk logs, but I cannot see nothing suspicious. I am not able to reproduce this behavior again by any way.

Is here someone with similar experience? Could someone give me hint what I should look for to find root cause of this behavior?

Best regards

Lukas

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...