Yes you can. But it's a bit of a manual effort, but worth the effort. The supression for 1 hour for user and dest will remain as it is in your alert's throttling. Now let's assume that user=Adam and dest=abc. A notable event is fired for this and is now in your incident review dashboard. You triage and decide to send it for remediation, as the system is infected by a malware, which will take 7 days. To enable suppression for these particular values of user and dest, follow these steps: 1. In Incident review dashboard, find the Incident. 2. Click on Actions tab's dropdown, belonging to this notable event, using which you decided to invoke supression. 3. Select Supress Notable Events. 4. Name your suppression whatever you want and set the duration for the suppression. In your case, for the next 7 days. Select the date range accordingly. 5. Selected fields option will be greyed out, but look at it's description and click change. 6. Verify if the values of user and dest are the same that you intended to, which should be the case as we properly chose the notable. If not, I'd recommend searching the notable properly, instead of modifying. That should be the last resort. 7. If you're happy with everything, click save. This will make sure that for a particular user and dest, you won't see a notable event for the next 7 days for this particular alert only. If the same user and dest are found in some other alert, let's say DLP Violations, you'll get an notable event. For the rest of the notable events, throttling remains at 1 hour. Let me know if this helps and how this works out. If it does, please mark this as an accepted answer. Thanks, S
... View more