Suppressed events
EyalSec hides events it can prove are harmless, without deleting them. This page explains what suppression is, how to see suppressed events, and how it affects severity.
What suppression is
When untrusted data reaches a risky operation, EyalSec also checks whether the data was made safe on the way. If it can prove the value could not change what the operation does (for example it was correctly escaped for exactly the kind of text the operation reads, or contains nothing that could break out of it), the event is marked suppressed and left out of the default view.
Nothing is deleted. A suppressed event is still stored, still counted, and one click away, unless you set an es-python machine to discard suppressed events. Suppression applies to the es-chromium list as well as es-python's.
Being conservative
Suppression only happens on proof. When EyalSec is not sure the value was safe, the event stays visible. Sanitizers that protect a value only in some situations (an escaping function that is right for one context but not another, for example) never suppress an event; at most they lower its severity by one level (see Severity caps).
The Show control
Show, in the shared part of the events toolbar, picks which events the list displays: Live only (the default) shows the events EyalSec could not prove safe, Suppressed only shows just the ones it could, and All events shows both.
In All events, suppressed rows carry a Suppressed tag and their impact tags lose their colour. The choice applies to every list and stays when you switch lists. Reset puts it back to Live only.
The sidebar counts follow this control, so with Suppressed only each product's count is its number of suppressed events.
The suppressed badge
The badge next to Show, for example 42 suppressed, is how many of your events are currently suppressed, across your whole account. It is hidden when there are none, so a quiet list never leaves you wondering whether nothing happened or everything was hidden.
The badge does not follow the filters or the list you are on, and it refreshes about once a minute.
Why an event was suppressed
Open a suppressed event to see why. On every list except es-python, the Sanitization block states in one sentence what made the value safe, or says "This value was not sanitized." for an ordinary event. See Event detail.
Severity caps
A suppressed event keeps its real severity, so if you show it you see what the finding would have been. An event whose data passed through a sanitizer that only protects it in some situations is not suppressed; instead its severity is lowered by one level (High becomes Medium, for example), so it never outranks the same flow with no protection at all.
Discard suppressed events
An es-python machine can be set to throw its suppressed events away when they arrive, instead of storing them. Set Discard suppressed events in the Suppressed events section of the machine's Configure window, or on the Filters page to set it for every machine.
| Choice | Effect |
|---|---|
| Default (keep) | suppressed events are stored and hidden, as described above |
| Keep | the same, set explicitly: use it to exempt one machine from a global Discard |
| Discard | suppressed events from the machine are dropped when they arrive and never stored |
A discarded event does not appear under Suppressed only or All events, in exports, or in the suppressed badge. The machine's other events are stored exactly as before. The change applies to the next events the machine sends, with no restart, because the machine keeps sending everything and EyalSec discards on arrival. Events already stored are not removed.
Discarding cannot be undone. EyalSec keeps improving how it recognises safe data, and a stored event is checked again when it does, so an event suppressed today can come back into your live view later. A discarded event was never stored, so that can never happen to it. Choose Discard only for machines where you are sure you will not want those events back.
Suppression is not a rule
Suppression is EyalSec's own judgement, event by event. To hide events you have decided you do not care about, use your own rules instead: block them from the row menu, add a filter on the Filters page, or set a rule with the Hide or Drop mode.