- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rroberts

Splunk Employee
02-26-2014
10:53 AM
Working in the esanalyst role I cannot suppress a notable event in ES 3.0.
Is this working as designed? If so, what capability do I need to give the role?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rroberts

Splunk Employee
10-09-2015
12:06 PM
To enable notable event suppression for esanalyst role add edit-suppressions to the role and make sure they have write permission in the SA-ThreatIntelligence app.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rroberts

Splunk Employee
10-09-2015
12:06 PM
To enable notable event suppression for esanalyst role add edit-suppressions to the role and make sure they have write permission in the SA-ThreatIntelligence app.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

AndySplunks
Communicator
01-26-2016
10:44 AM
I gave my ess_analysts the edit-suppressions role. They don't have write access to SA-ThreatIntelligence though and aren't experiencing any problems yet.
