cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Access VMworld content on-demand if you missed the event. 70+ security focused sessions were offered -- access requires registration.

Carbon Black Cloud: How to Dismiss Alerts

Carbon Black Cloud: How to Dismiss Alerts

Environment

  • Carbon Black Cloud (Formerly PSC) Console: All Versions

Objective

How to dismiss alerts for different purposes and how to check if an alert is dismissed properly.

There are 2 options for dismissing alerts:

1. Dismiss a single alert (to only dismiss a single incident on a single device, and not affect future similar incidents)

2. Dismiss all similar alerts in the future (to dismiss all similar current and future incidents from any devices in the org)


Resolution

Dismiss A Single Alert

  1. Log in to the Carbon Black Cloud Console and go to the "Alerts" page
  2. Switch the "Group Alerts" toggle OFF, then click on the drop down button of the target alert and click on "Dismiss"
  3. When the Dismiss Activity confirmation window pops up, confirm the information and leave comments if needed, then click "DISMISS"
  4. The dismissed alert should now be grayed-out on the Alerts page.

Dismiss Grouped Alerts Across All Devices

  1. Log in to the Carbon Black Cloud Console and go to the "Alerts" page
  2. Switch the "Group Alerts" toggle ON, then click on the drop down button of the target alert and click on "Dismiss on all devices"
  3. When the Dismiss Activity confirmation window pops up, confirm the information and leave comments if needed, making sure "If this alert occurs in the future, automatically dismiss it from all devices" is checked and click "DISMISS"
  4. Similar alerts with same Threat ID should all be dismissed and grayed-out on the Alerts page. See Cb Defense: Alert ID vs. Threat ID  for additional information.

Check if an alert is dismissed properly

  1. Log in to the Carbon Black Cloud Console and go to the Alerts page, then find the target Alert you want to check.
  2. Click on the Alert Triage buttonScreen Shot 2018-04-12 at 10.01.45 AM.png
  3. Scroll down to find the "ALERT NOTES & TAGS" section, and check the latest dismissing event.
  4. If the Message in the result shows "Dismissed alert xxxxxxxxxxx on device xxxxxxx......", this indicates a single incident was dismissed on a single device.
  5. If the Message in the result shows "Dismissed x alert in threat xxxxxxxxxxxx on all devices, as well as all future occurrences......", this indicates all similar threats under same ThreatID have been dismissed.
  6. To also determine if the dismissal was applied to future instances from the description of that action.

Additional Notes

  • There is no way to dismiss an alert with "Group Alert" OFF and "If this alert occurs in the future, automatically dismiss it from all devices" checked, it will not affect any future new instances.
  • Dismissing alerts is not instantaneous; there is a time delay.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎07-19-2017
Views:
3136