Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Splunk Enterprise Security: How to display all notable events and indicate which ones were suppressed?

$
0
0
My SOC wants a page showing all recent notables, and which ones were suppressed by the current suppression rules. Obviously I can list notables with index=notable but how can I easily indicate the ones that actually showed up in Incident Review vs. the ones that were suppressed?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>