Splunk Search

Splunk ES - Notification when a suppression is created

daniel333
Builder

Hello,

Is there a way to get a RSS or email notification when a new notable suppression is created or enabled in ES?

0 Karma

mparks11
Path Finder

You can create an alert and send an email for the following:

index=_internal sourcetype=notable_event_suppression:rest_handler "SuppressionAudit" action=create.

I know this is an old question, but have been doing some research lately myself and came upon this :). It only seems to apply when creating a suppression from ES either through Incident Review workflow action or through Notable Event Suppression page under Content Management --> Incident Review (I believe - working from memory presently).

AndySplunks
Communicator

You can create an alert to periodically run that monitors for new suppression. That would be the fastest way.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...