Splunk Search

Splunk ES - Notification when a suppression is created

daniel333
Builder

Hello,

Is there a way to get a RSS or email notification when a new notable suppression is created or enabled in ES?

0 Karma

mparks11
Path Finder

You can create an alert and send an email for the following:

index=_internal sourcetype=notable_event_suppression:rest_handler "SuppressionAudit" action=create.

I know this is an old question, but have been doing some research lately myself and came upon this :). It only seems to apply when creating a suppression from ES either through Incident Review workflow action or through Notable Event Suppression page under Content Management --> Incident Review (I believe - working from memory presently).

AndySplunks
Communicator

You can create an alert to periodically run that monitors for new suppression. That would be the fastest way.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...