Splunk Enterprise Security

Notable event suppression active even after expiration time

lukasmecir
Path Finder

Hello,

I have SH cluster with Enterprise Security deployed (Splunk version 8.0.4.1, Ent. Security 6.2.0). I created Notable event suppression for particular Notable event (using Incident Review dashboard). I set Expiration time for this suppression. Everything worked as expected. But then I found that NE suppression is still active, even after expiration time - no NE visible in Incident Review dashboard.  (But there were Notable Events  in notable index all the time, as expected). In other words, Splunk simply ignored Expiration time of NE suppression and behave as NE suppression was set without Expiration time. Notable Events became visible in Incident Review after NE suppression was manually disabled and from this point everything work as expected.

There are few other NE suppressions and all works as expected.

I examined Splunk logs, but I cannot see nothing suspicious. I am not able to reproduce this behavior again by any way.

Is here someone with similar experience? Could someone give me hint what I should look for to find root cause of this behavior?

Best regards

Lukas

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...