All Apps and Add-ons

Splunk App for AWS: Is there a way to ignore specific vulnerabilities within search results on Amazon Inspector dashboard?

klaxdal
Contributor

Wondering if there is a way to not include / ignore specific vulnerabilities within search results on the Insights > Amazon Inspector dashboard?

There are several "High" vulnerabilities that are present in my environment that I would like to suppress in the results e.g. Windows Firewall (we are using a third party product)

I have my gold image and would like all residual vulnerabilities to not appear in the results - only the ones which are "net new" and have not been vetted.

If this is not possible, perhaps this functionality can be included in the next version?

0 Karma
1 Solution

hunters_splunk
Splunk Employee
Splunk Employee

Hi klaxdal,

Currently, the Amazon Inspector Insights dashboard does not let you easily suppress and filter out data you don't want. I will reach out to the product team to let them know about this requirement.

However, the recent 5.0.0 release introduces the feature below:
Configure anomaly detection rules for detecting anomalies in AWS account access activity and billing records in the Security Anomaly Insights dashboard and Billing Anomaly Insights dashboard respectively.

Hope this helps. Thanks!
Hunter

View solution in original post

0 Karma

hunters_splunk
Splunk Employee
Splunk Employee

Hi klaxdal,

Currently, the Amazon Inspector Insights dashboard does not let you easily suppress and filter out data you don't want. I will reach out to the product team to let them know about this requirement.

However, the recent 5.0.0 release introduces the feature below:
Configure anomaly detection rules for detecting anomalies in AWS account access activity and billing records in the Security Anomaly Insights dashboard and Billing Anomaly Insights dashboard respectively.

Hope this helps. Thanks!
Hunter

0 Karma

klaxdal
Contributor

Thanks Hunter

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...