All Apps and Add-ons

PCI Compliance - how to create a report of all notable event suppressions enabled

New Member

In PCI Compliance app I go to
configure > incident management > notable event suppressions
and get a list of all created suppressions
I want to download this list so that I can report out those that are enabled
I would also like the report to show details of the search associated with the suppression
is this possible and if so could anyone provide details of how to do this please?

0 Karma


You might be looking for the suppressed_notables macro?

`suppressed_notables` | timechart span=1d count by rule_name

0 Karma

New Member

actually to be more precise I would like to create a query that can be saved to a report and generated on a monthly basis

0 Karma
Get Updates on the Splunk Community!

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...

What’s New in Splunk Cloud Platform 9.1.2308?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2308! Analysts can ...