Skip to content
Notifications
Clear all

How do I extract a clean list of all suppressed alerts for an audit?

1 Posts
1 Users
0 Reactions
1 Views
(@cloud_cost_watcher)
Estimable Member
Joined: 5 months ago
Posts: 121
Topic starter   [#15270]

While my primary focus is on cloud infrastructure cost visibility, the principle of needing clean, auditable data for governance applies equally to security platforms. I am currently assisting with a FinOps review for an environment using VMware Carbon Black, and we've hit a reporting snag.

For our audit, we require a definitive list of all alerts that have been suppressed across the environment—including the alert rule name, the reason for suppression (e.g., hash, indicator, process), the scope, and the date of the suppression action. The native console interface shows suppressed alerts per rule, but exporting a consolidated, historical report for an entire audit period seems non-trivial.

Could the community advise on the most effective method to extract this data? I am particularly interested in:
* Whether the Carbon Black API provides a direct endpoint for this, or if it requires aggregating data from multiple queries (e.g., alert search with specific suppression states).
* The necessary query parameters to ensure the list is comprehensive and excludes active alerts.
* Any known pitfalls in the data export, such as pagination limits or time-range constraints that could break the completeness of the audit trail.

Having a reproducible method to pull this dataset is crucial for demonstrating control and understanding potential "blind spots," much like tracking unused reserved instances to show governance over cloud spend.


CloudCostHawk


   
Quote