Splunk Search

Splunk ES - Notification when a suppression is created

daniel333
Builder

Hello,

Is there a way to get a RSS or email notification when a new notable suppression is created or enabled in ES?

0 Karma

mparks11
Path Finder

You can create an alert and send an email for the following:

index=_internal sourcetype=notable_event_suppression:rest_handler "SuppressionAudit" action=create.

I know this is an old question, but have been doing some research lately myself and came upon this :). It only seems to apply when creating a suppression from ES either through Incident Review workflow action or through Notable Event Suppression page under Content Management --> Incident Review (I believe - working from memory presently).

AndySplunks
Communicator

You can create an alert to periodically run that monitors for new suppression. That would be the fastest way.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...