I'm looking to create a dashboard of existing suppression's, and those that have recently expired or will expire in the near future.
But I'm struggling to find where I can extract the relevant >=time and <=time used within the suppression.
notable
includes the suppression name, but not when it expires. Cant seem to find where this is stored. Any ideas?
I had this question as well, because I wanted to set up alerts around soon to expire suppressions. I found an out-of-box macro that gathers the relevant info using the "rest" search command.
| suppression_eventtypes
I had this question as well, because I wanted to set up alerts around soon to expire suppressions. I found an out-of-box macro that gathers the relevant info using the "rest" search command.
| suppression_eventtypes
Thats exactly what I was after. Thanks!