Paul,
As @gjanders is hinting at with his question, the appropriate suppress syntax may change in terms of what is most appropriate for what you are trying to suppress. My error is worded slightly differently than the example given above. I have tried the following edit to my config at /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/local/inputs.conf
[configuration_check://confcheck_es_app_version]
interval = 86400
default_severity = INFO
required_ui_severity = WARN
suppress = (.*data_migrator.py)
debug = False
... View more