There may be situations in which you prefer not to see specific alerts. For example, while you are responding to a potential compromise, you may want to suppress further alerts about that compromise. You can suppress alerts that match an existing alert’s rule ID for a period of time. When you suppress an alert, new incoming alerts with the suppressed rule ID will not be visible in the Alerts table for period of time you select to suppress the alert.
Note
When an alert is suppressed, only the alert itself is suppressed. The rule that triggered the alert remains active.
To suppress alerts:
On the Alerts page, do one of the following:
For a single alert, at the end of the row click More Options
> Suppress.For multiple alerts, select the checkbox next to each alert name and click Actions > Suppress.
Note
If you select fewer than 1,000 alerts, the update happens in real time. If you select more than 1,000 alerts, the update happens in the background and you cannot perform the action again until the process is finished.
In the dialog, select a period of time from the menu and enter an optional note.
Click Save.
You can also click on an alert and select More Options
> Suppress in the upper right of the page.