A suppression rule is a set of attribute-based filter criteria that defines cases where you want Amazon Macie to archive findings automatically. Suppression rules are helpful in situations where you've reviewed a class of findings and don't want to be notified of them again. When you create a suppression rule, you specify filter criteria, a name, and, optionally, a description of the rule. Macie then uses the rule's criteria to determine which findings to archive automatically. By using suppression rules, you can streamline your analysis of findings.
If you suppress findings with a suppression rule, Macie continues to generate findings for subsequent occurrences of sensitive data and potential policy violations that match the rule's criteria. However, Macie automatically changes the status of the findings to archived. This means that the findings don't appear by default on the Amazon Macie console, but they persist in Macie until they expire. (Macie stores findings for 90 days.) This also means that Macie doesn't publish the findings to Amazon EventBridge as events or to AWS Security Hub.
Note that suppression rules might work differently for your account, if your account is part of an organization that centrally manages multiple Macie accounts. This depends on the category of findings that you want to suppress, and whether you have a Macie administrator or member account:
-
Policy findings – Only a Macie administrator can suppress policy findings for the organization's accounts.
If you have a Macie administrator account and you create a suppression rule, Macie applies the rule to policy findings for all the accounts in your organization unless you configure the rule to exclude specific accounts. If you have a member account and you want to suppress policy findings for your account, work with your Macie administrator to suppress the findings.
-
Sensitive data findings – A Macie administrator and individual members can suppress sensitive data findings that their sensitive data discovery jobs produce. A Macie administrator can also suppress findings that Macie generates while performing automated sensitive data discovery for the organization.
Only the account that creates a sensitive data discovery job can suppress or otherwise access sensitive data findings that the job produces. Only the Macie administrator account for an organization can suppress or otherwise access findings that automated sensitive data discovery produces for accounts in the organization.
For more information about the tasks that administrators and members can perform, see Macie administrator and member account relationships.
Also note that suppression rules are different from filter rules. A filter rule is a set of filter criteria that you create and save to use again when you review findings on the Amazon Macie console. Although both types of rules store and apply filter criteria, a filter rule doesn't perform any action on findings that match the rule's criteria. Instead, a filter rule only determines which findings appear on the console after you apply the rule. For more information, see Defining filter rules. Depending on your analysis goals, you might determine that it's best to create a filter rule instead of a suppression rule.
To create a suppression rule for findings
You can create a suppression rule by using the Amazon Macie console or the Amazon Macie API. Before you create a suppression rule, it's important to note that you can't restore (unarchive) findings that you suppress using a suppression rule. You can, however, review suppressed findings by using Macie.
Follow these steps to create a suppression rule by using the Amazon Macie console.
To create a suppression rule
Open the Amazon Macie console at https://console.aws.amazon.com/macie/
. -
In the navigation pane, choose Findings.
Tip
To use an existing suppression or filter rule as a starting point, choose the rule from the Saved rules list.
You can also streamline creation of a rule by first pivoting and drilling down on findings by a predefined logical group. If you do this, Macie automatically creates and applies the appropriate filter conditions, which can be a helpful starting point for creating a rule. To do this, choose By bucket, By type, or By job in the navigation pane (under Findings). Then choose an item in the table. In the details panel, choose the link for the field to pivot on.
-
In the Filter criteria box, add filter conditions that specify attributes of the findings that you want the rule to suppress.
To learn how to add filter conditions, see Creating and applying filters to Macie findings.
-
When you finish adding filter conditions for the rule, choose Suppress findings.
-
Under Suppression rule, enter a name and, optionally, a description of the rule.
-
Choose Save.