<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where are Noteable Event Suppressions stored in Splunk? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/598551#M10806</link>
    <description>&lt;P&gt;Why was this answer accepted?&amp;nbsp; It does not answer the question AT ALL!&amp;nbsp; See my answer which does.&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2022 18:43:52 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2022-05-19T18:43:52Z</dc:date>
    <item>
      <title>Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50023#M128</link>
      <description>&lt;P&gt;In Enterprise Security, you can configure Notable Event Suppressions.  When adding/editing a suppression, which file exactly is getting updated within Splunk?  I've been looking in /etc/apps/SplunkEnterpriseSecuritySuite but I haven't found the file there (yet).&lt;/P&gt;

&lt;P&gt;The reason I ask is because I edited a suppression and now the 'notable event suppression' GUI doesn't work and I need to manually fix the suppression by modifying it in the file system.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2013 17:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50023#M128</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-08-28T17:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50024#M129</link>
      <description>&lt;P&gt;Hi. Do you mean the GUI doesn't display at all? This section in the ES docs describes how to create a new suppression:  &lt;A href="http://docs.splunk.com/Documentation/ES/latest/Install/NotableEventSuppression#Suppress_notable_events_from_new_correlation_searches"&gt;http://docs.splunk.com/Documentation/ES/latest/Install/NotableEventSuppression#Suppress_notable_events_from_new_correlation_searches&lt;/A&gt; with the names of the files you would need to edit. You might check there first. &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2013 19:41:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50024#M129</guid>
      <dc:creator>jmckean_splunk</dc:creator>
      <dc:date>2013-08-28T19:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50025#M130</link>
      <description>&lt;P&gt;Hi, I broke the GUI/webpage by blanking out the description and search fields in a suppression.  If you do this, then you will get a webpage rendering error when trying to view the Notable Event Suppressions from within the GUI, I guess it doesn't know how to display a blank suppression.&lt;/P&gt;

&lt;P&gt;I was able to find the .conf file and edit the file manually which fixed the GUI problem.  This is the file that I was looking for (it's also referenced in the document you mentioned) that stores all of the event suppressions (that the GUI reads from):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;etc/apps/SA-ThreatIntelligence/local/eventtypes.conf
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 28 Aug 2013 19:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50025#M130</guid>
      <dc:creator>echojacques</dc:creator>
      <dc:date>2013-08-28T19:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50026#M131</link>
      <description>&lt;P&gt;Feels like this question remains unanswered. &lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 22:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/50026#M131</guid>
      <dc:creator>morethanyell</dc:creator>
      <dc:date>2019-09-25T22:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/598551#M10806</link>
      <description>&lt;P&gt;Why was this answer accepted?&amp;nbsp; It does not answer the question AT ALL!&amp;nbsp; See my answer which does.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 18:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/598551#M10806</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2022-05-19T18:43:52Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/598553#M10807</link>
      <description>&lt;P&gt;They are stored as `eventtypes`.&amp;nbsp; Search for "notable_suppression".&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 18:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/598553#M10807</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2022-05-19T18:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/654958#M11665</link>
      <description>&lt;P&gt;See my answer.&amp;nbsp; The accepted answer is useless.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Aug 2023 14:16:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/654958#M11665</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2023-08-19T14:16:33Z</dc:date>
    </item>
    <item>
      <title>Re: Where are Noteable Event Suppressions stored in Splunk?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/699850#M12085</link>
      <description>&lt;P&gt;This is the right answer&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 14:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Where-are-Noteable-Event-Suppressions-stored-in-Splunk/m-p/699850#M12085</guid>
      <dc:creator>sarcome</dc:creator>
      <dc:date>2024-09-23T14:10:01Z</dc:date>
    </item>
  </channel>
</rss>

