Splunk Enterprise Security

Notable Event Suppression option missing in actions drilldown

capnjudge
New Member

I was given admin rights at my job recently to work suppressions, and I have the ability to go to the notable event suppressions menu and do suppressions there, but when I go to incident review and attempt to suppress from there, the option "Suppress Notable Events." is not there. Is there some sort of option I need to turn on or am I missing something entirely different?

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @capnjudge,

You should go Configure | Incident Management | Notable Event Suppressions page;

https://docs.splunk.com/Documentation/ES/6.4.1/Admin/Customizenotables#Create_and_manage_notable_eve...  

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...