create-security-suppression
Create a suppression rule to mute security signals from specified detection rules, with optional suppression query, data exclusion, and expiration date.
Instructions
Create a security monitoring suppression rule to suppress signals matching a query
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Name of the suppression rule | |
| ruleQuery | Yes | Rule query — detection rules matching this query will have signals suppressed. Same syntax as search bar | |
| description | No | Description of the suppression rule | |
| enabled | No | Whether the suppression rule is enabled (default true) | |
| suppressionQuery | No | Suppression query — signals matching this query are suppressed | |
| dataExclusionQuery | No | Data exclusion query — input events matching this are excluded from detection | |
| expirationDate | No | ISO 8601 expiration date — after this date, suppression stops |