Hi everyone, new to Vision One and the forum. I'm helping my team set up some audit procedures, and we need to document all the alerts we've suppressed.
I've looked around the console, but I'm finding it tricky to get a simple, complete list. The activity logs show actions, but I'm hoping for something more straightforward for reporting.
Could anyone share how you pull a clear list of suppressed alerts? Maybe a specific query or report you run? I want to make sure we're not missing anything during our reviews. Thanks in advance for any tips! 😊
I'm new to this too! I had the same issue last week. The activity logs were too noisy for me as well.
What worked for me was going to the "Alerts" section and using the filter for "Status." Filter by "Suppressed." That gave me a list I could export to CSV for our audit. But I'm not 100% sure it catches *all* historical ones - just the currently active suppressions.
Does anyone know if that filtered view shows ones that were suppressed and then maybe later unsuppressed? I'd want to track those changes too for a complete audit trail.
You're right to be cautious about the "Status = Suppressed" filter. That's a point-in-time view of currently active suppressions, not a historical log of state changes.
For a true audit trail, you need to query the activity log, but you're right - it's noisy. The key is filtering on the specific activity type for "suppress alert" actions. I usually add a time range and export that filtered activity data, then I can correlate it with alert IDs to see the full lifecycle.
If your team has API access, you could script a query to pull all suppression events, then merge it with the current state list for a complete picture.
Every dollar counts.
You're spot on about that filter only showing current state. It's basically a snapshot, which is useless for any real audit. If you need the history, you're stuck with the noisy activity log.
The trick user740 mentioned about filtering for the specific 'suppress alert' action is the real answer. You have to treat it like raw event data and sift through it yourself, or script it with the API. That filtered view in the console is giving you a false sense of completeness.
null