According to the Splunk Enterprise Security documentation, the Status Configuration window allows you to customize the status values and transitions for notable events. You can define which roles can change the status of a notable event from one value to another, and which roles can view the notable events with a specific status. To restrict the users with the ess_user role from being able to change the status of Resolved notable events to closed, you need to do the following steps:
On the Enterprise Security menu bar, select Configure > Incident Management > Status Configuration.
In the Status Configuration window, select the Resolved status from the list of values.
In the Status Transitions section, find the row for the closed status and click the Edit icon.
In the Edit Status Transition dialog box, remove the ess_user role from the Roles field and click Save.
Click Save Changes to apply the changes to the Status Configuration window.
This will prevent the users with the ess_user role from changing the status of any notable event from Resolved to closed. They will still be able to change the status of other notable events to closed, if they have the permission to do so. Therefore, the correct answer is A. From the Status Configuration window select the Resolved status. Remove ess_user from the status transitions for the closed status. References = Customize status values and transitions for notable events.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit