Splunk Enterprise Security

Splunk Rules: How to suppress threat activity alert into one

pavanbmishra
Path Finder

Hello Dears,

We usually see the threat correlation alert suppressed basis on the filed specified as per snap attached. It does work when there is any suspicious IP address reported, but not for URLs, say if the domain is registered as blacklisted and if the traffic hitting to that domain having different URLs, it triggered all those alerts.

How can we suppress these into one, if the domain is the same? Added additional field (threat_collection_key) to suppress URLs but seems not working here. Is there any workaround?

alt text

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...