Splunk Enterprise Security

Splunk Enterprise Security: Why is the alert "Activity from an expired identity" getting triggered when no identities have expired?

andresito123
Communicator

I have populated identities.csv on Splunk Enterprise Security and enabled the alert of "Activity from an expired identity". Although the identity is not expired, the alerts are being generated. Do you have any ideas on how to correct this issue?

My identities.csv looks like the following:

identity,prefix,nick,first,last,suffix,email,phone,phone2,managedBy,priority,bunit,category,watchlist,startDate,endDate,work_city,work_country,work_lat,work_long
xxx,Mr.,,xxx,xxx,,xxx,,,xxx,,xxx,contractor,true,,01/31/17 23:59,xxx,xxx,,
xxx,Ms.,,xxx,xxx,,xxx,,,xxx,,xxx,contractor,true,,01/31/17 23:59,xxx,xxx,,
0 Karma

avisram_splunk
Splunk Employee
Splunk Employee

What version of Enterprise Security is this on? Your issue might be related to this:

https://answers.splunk.com/answers/442556/splunk-expired-account-activity.html

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...