%3CLINGO-SUB%20id%3D%22lingo-sub-1404920%22%20slang%3D%22en-US%22%3ESuppression%20rules%20for%20Azure%20Security%20Center%20alerts%20are%20now%20available%20in%20public%20preview%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1404920%22%20slang%3D%22en-US%22%3E%3CP%3ESuppression%20rules%20giving%20the%20ability%20to%20fine-tune%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Fsecurity-center-alerts-overview%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3EAzure%20Security%20Center%20alerts%3C%2FA%3E%20by%20your%20organizations'%20specific%20needs%20and%20conditions%2C%20letting%20you%20suppress%20alerts%20that%20are%20triggered%20by%20known%20normal%20activities%20in%20your%20organization.%26nbsp%3BUse%20suppression%20rules%20to%20suppress%20alerts%20that%20are%20known%20to%20be%20inoffensive%2C%20thus%20reducing%20alerts%20fatigue%20for%20your%20SOC%20team.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESuppressed%20alerts%20will%20be%20hidden%20in%20Azure%20Security%20Center%2C%20Azure%20Sentinel%20and%20third-party%20SIEM%20solutions%2C%26nbsp%3Bbut%20will%20still%20be%20reachable%20if%20needed%20later%20on%20with%20dismissed%20state.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E%3CFONT%20size%3D%224%22%3EHow%20to%20suppress%20alert%20in%20Azure%20Security%20Center%3F%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20suppress%20alerts%20in%20Azure%20Security%20Center%2C%20follow%20the%20following%20guidelines%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EGo%20to%20'Security%20Alerts'%20page%20in%20Azure%20Security%20Center.%3C%2FLI%3E%0A%3CLI%3EChoose%20the%20alert%20you%20would%20like%20to%20suppress%2C%20click%20on%20the%20three%20dots%20at%20the%20end%20of%20the%20row%2C%20and%20choose%20'Create%20suppression%20rule'%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22suppressmain.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F194253i9810D9D9639F4253%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22suppressmain.png%22%20alt%3D%22suppressmain.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E3.%20In%20the%20'new%20suppression%20rules'%20page%20-%20Choose%20the%20alert%20you%20would%20like%20to%20suppress%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E4.%20Choose%20the%20entities%20you%20would%20like%20to%20suppress%20the%20alert%20for%2C%20for%20example%3A%20suppress%20the%20alert%20only%20for%20specific%20IP%20ranges%2C%20processes%2C%20resources%2C%20or%20user%20accounts%20(The%20best%20practice%20is%20to%20refine%20the%20suppression%20rule%20and%20suppress%20as%20less%20alerts%20as%20possible)%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditortal_rosler_3%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22suppress.png%22%20style%3D%22width%3A%20274px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F194251iF0496477635FC3E4%2Fimage-dimensions%2F274x462%3Fv%3D1.0%22%20width%3D%22274%22%20height%3D%22462%22%20title%3D%22suppress.png%22%20alt%3D%22suppress.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E5.%20Enter%20rule%20details%3A%20Rule%20name%2C%20Reason%20for%20suppression%2C%20comment%20and%20expiration%20date%20(up%20to%206%20months%20ahead)%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E6.%20Click%20on%20'simulate'%20to%20test%20your%20rule%20before%20you%20are%20applying%20it%20and%20validate%20it's%20correctness.%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E7.%20Click%20on%20apply.%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E8.%20To%20manage%20your%20suppression%20rules%2C%20click%20on%20'Suppression%20rules'%20button%20at%20the%20head%20of%20'Security%20alerts'%20page%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20more%20information%2C%20reach%20out%20to%20our%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fsecurity-center%2Falerts-suppression-rules%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Edocumentation%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETal%20Rosler%2C%3C%2FP%3E%0A%3CP%3EProduct%20Manager%2C%3C%2FP%3E%0A%3CP%3EAzure%20Security%20Center.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Suppression rules giving the ability to fine-tune Azure Security Center alerts by your organizations' specific needs and conditions, letting you suppress alerts that are triggered by known normal activities in your organization. Use suppression rules to suppress alerts that are known to be inoffensive, thus reducing alerts fatigue for your SOC team. 

 

Suppressed alerts will be hidden in Azure Security Center, Azure Sentinel and third-party SIEM solutions, but will still be reachable if needed later on with dismissed state.

 

How to suppress alert in Azure Security Center?

 

To suppress alerts in Azure Security Center, follow the following guidelines:

 

  1. Go to 'Security Alerts' page in Azure Security Center.
  2. Choose the alert you would like to suppress, click on the three dots at the end of the row, and choose 'Create suppression rule'

suppressmain.png

 

3. In the 'new suppression rules' page - Choose the alert you would like to suppress

4. Choose the entities you would like to suppress the alert for, for example: suppress the alert only for specific IP ranges, processes, resources, or user accounts (The best practice is to refine the suppression rule and suppress as less alerts as possible)

 

suppress.png

 

5. Enter rule details: Rule name, Reason for suppression, comment and expiration date (up to 6 months ahead)

6. Click on 'simulate' to test your rule before you are applying it and validate it's correctness.

7. Click on apply.

8. To manage your suppression rules, click on 'Suppression rules' button at the head of 'Security alerts' page

 

For more information, reach out to our documentation.

 

 

Tal Rosler,

Product Manager,

Azure Security Center.