Customizations let you tailor how Zscaler MDR reviews “Suspicious Activity” threats, helping reduce false positives and irrelevant notifications. Use this page to view and get notified about suppressed alerts.
Viewing Suppressed Threats
Suppressed threats are available in the Zscaler MDR portal, or via API (add state=suppressed to your GET request).
In your Zscaler MDR portal, go to the Threats page.
Click the filter icon.

From the State dropdown, select Suppressed.

Click Apply Filters.
Click on a threat to see a detailed explanation from the Threat Review Agent, including a link to the applied customization.
Note
Reopening a suppressed threat does not add it to reports or statistics; it will remain excluded from reporting.
Configuring Notifications for Suppressed Threats
Customizations are designed to reduce excessive notifications caused by false positives. However, if you would like to monitor the initial performance of your customizations, you can set up notifications using the Automation trigger “When a Threat is suppressed.” This trigger alerts you when a threat is suppressed prior to publication.
In your Zscaler MDR portal, go to Automations and click Configure New Trigger.
Select When a Threat is suppressed.
Click Connect Playbook next the trigger you created.
Click Add Action and configure your preferred notification method.
Click Save.