Documentation Center
AlienVault® USM Anywhere™

Suppressing/Unsuppressing Events

  Role Availability   Read-Only   Analyst   Manager

Not all eventsAny traffic or data exchange detected by AlienVault products through a Sensor, or through external devices such as a firewall. found during monitoringProcess of collecting all device status and event information and processing normalized events for evidence of vulnerabilities, possible attacks, and other malicious activity. are necessary in managing your environment. Frequently, there are events that create a noisy environment, making it difficult to monitor other events that require more attention. You can identify these events and suppress them before executing any processing by the correlation engineUsed in systems management tools to aggregate, normalize, and analyze event log data, using predictive analytics and fuzzy logic to alert the systems administrator when there is a problem.. It is also possible that you may not want to suppress the events as you might have to be aware of other impacted systems.

USM Anywhere saves the events that match a suppression rule, but does not correlate these suppressed events. By default, USM Anywhere hides these suppressed events. If you want to see these events, click Suppressed in the Search & Filters area. The suppressed events will be displayed in the table along with all events. If you want to display just the suppressed events, see To only display the suppressed events.

Note: The suppression rule you create will apply to future events. It also will apply to events of the current day, up to 10K events.

To suppress an event

  1. Navigate to ACTIVITY > EVENTS.
  2. Click on the event to suppress.
  3. Click Suppress Event.

To unsuppress an event

  1. Navigate to ACTIVITY > EVENTS.
  2. Search the suppressed events by using the filter Suppressed. See Searching Events for more information.
  3. Click the event to unsuppress.
  4. Click Unsuppress Event.

To only display the suppressed events

  1. Navigate to ACTIVITY > EVENTS.
  2. Click the Configure Filters link, which is positioned at the lower-right area of the filters.
  3. Write in the Search filters field 'Suppress'.
  4. Select the Suppress Rule Name filter.
  5. Click the Right Arrow icon ().
  6. The selected filter will pass from the available filters to the selected filters.

  7. Click Apply.
  8. The dashboard view will reset and the Suppress Rule Name filter will be available.

  9. Click Suppressed in the Search & Filters area.
  10. Search the Suppress Rule Name filter and click on the rule.
  11. If there are no rule names displayed it is because

    • there are no events suppressed by the rule
    • the Suppressed filter is not enabled

    See Searching Events for further information about the icons below the filters.

Note: You can save the view for later use. See Event Views for further information about how to create a configuration view.