A suppression rule is a set of criteria that includes using filter attributes and providing values for which you don't want GuardDuty to generate a finding type. The finding types that match this criteria are automatically archived. To reduce noise, the suppressed findings are not sent to any of the AWS services with which you may integrate. For more information about common use cases for creating suppression rules, see Suppression rules.
You can visualize, create, and manage suppression rules by using the GuardDuty console. Suppression rules are generated in the same manner as filters, and your existing saved filters can be used as suppression rules. For more information about creating filters, see Filtering findings in GuardDuty.
Choose your preferred access method to create a suppression rule for GuardDuty finding types.
To create a suppression rule using the console:
Open the GuardDuty console at https://console.aws.amazon.com/guardduty/
. -
On the Findings page, the Create suppression rule feature remains grayed out unless you add at least one filter criterion. Because suppression rules are applied to active, ongoing findings, make sure that the Status menu is set to Current.
-
To add one or more filter criteria, follow steps 3 through 7 in Adding filters on Findings page, and then continue with the following steps.
-
After you have added the filter criteria and confirmed that the filtered findings meet your requirements, choose Create suppression rule.
-
Enter a Name for the suppression rule.The name must be 3-64 characters. Valid characters are a-z, A-Z, 0-9, period (.), hyphen (-), and underscore (_).
-
The Description is optional. If you enter a description, it can have up to 512 characters.
-
Choose Create.
You can also create a suppression rule from an existing saved filter. For more information about creating filters, see Filtering findings in GuardDuty.
To create a suppression rule from a saved filter:
Open the GuardDuty console at https://console.aws.amazon.com/guardduty/
. -
On the Findings page, from the Saved rules menu, select a saved filter set rule. This will automatically display the filter set and findings that match the criteria.
-
You can also add more filter criteria to this saved rule. If you don't need additional filter criteria, skip this step.
To add one or more additional filter criteria, follow steps 2 through the end of the preceding procedure - To create a suppression rule using the console.
-
If you don't need to add additional filter criteria to the saved rule, follow steps 4 through the end of the preceding procedure - To create a suppression rule using the console.