Splunk Search

Splunk ES - Notification when a suppression is created

daniel333
Builder

Hello,

Is there a way to get a RSS or email notification when a new notable suppression is created or enabled in ES?

0 Karma

mparks11
Path Finder

You can create an alert and send an email for the following:

index=_internal sourcetype=notable_event_suppression:rest_handler "SuppressionAudit" action=create.

I know this is an old question, but have been doing some research lately myself and came upon this :). It only seems to apply when creating a suppression from ES either through Incident Review workflow action or through Notable Event Suppression page under Content Management --> Incident Review (I believe - working from memory presently).

AndySplunks
Communicator

You can create an alert to periodically run that monitors for new suppression. That would be the fastest way.

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>