Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Table ES Suppressions including start time and end time

$
0
0
I'm looking to create a dashboard of existing suppression's, and those that have recently expired or will expire in the near future. But I'm struggling to find where I can extract the relevant >=time and <=time used within the suppression. `notable` includes the suppression name, but not when it expires. Cant seem to find where this is stored. Any ideas?

Viewing all articles
Browse latest Browse all 47296

Trending Articles