How to exclude device from all Alerts?


We utilise Enterprise Security and have a large number of detections that we use.  We have recently put in some testing hardware that could trigger any one of these alerts and I am trying to find out if there is someway that we could suppress or exclude a device if that host potentially triggered these rules.  Is there a way to effectively do a global "ignore any alerts from xxxx" without having to edit every single rule?

Labels (1)
Tags (2)
0 Karma


Hi @willadams,

no, for my knowledge, there isn't any exclusion list in ES, the only way is to customize your correlation searches.

It could be a good idea to submit this request to Splunk Ideas for the new features of ES.



0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...