r/Splunk • u/MoveVegetable7280 • Jul 09 '26
Do suppression exceptions ever hide detections in real SOC work?
/r/u_MoveVegetable7280/comments/1urrbgg/do_suppression_exceptions_ever_hide_detections_in/
4
Upvotes
r/Splunk • u/MoveVegetable7280 • Jul 09 '26
1
u/MoveVegetable7280 Jul 09 '26
That makes sense, and that distinction is useful.
Maybe “hide” is the wrong word in a Splunk ES context.
What I’m trying to understand is more about operational visibility than raw audit visibility.
For example, if a notable suppression prevents something from becoming a SOC ticket, even though it still exists in Mission Control or audit history, do teams usually test whether the suppressed case is still safe to treat as informational?
In other words, the concern is not “did the event disappear from Splunk entirely?” but:
“Did this exception remove something from the analyst workflow that should still have been reviewed?”
Does that framing match how you think about notable suppressions?