All Apps and Add-ons

PCI Compliance - how to create a report of all notable event suppressions enabled

vincenp2
New Member

In PCI Compliance app I go to
configure > incident management > notable event suppressions
and get a list of all created suppressions
I want to download this list so that I can report out those that are enabled
I would also like the report to show details of the search associated with the suppression
is this possible and if so could anyone provide details of how to do this please?

0 Karma

Lorne_2
Engager

You might be looking for the suppressed_notables macro?

ex:
`suppressed_notables` | timechart span=1d count by rule_name

0 Karma

vincenp2
New Member

actually to be more precise I would like to create a query that can be saved to a report and generated on a monthly basis

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...