Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Cb Defense: Still Getting Notifications For Alerts I Have Dismissed

Cb Defense: Still Getting Notifications For Alerts I Have Dismissed

Environment

  • Cb Defense Web Console: All Versions

Symptoms

  • Alerts dismissed previously
  • New Alerts showing up with the same Tactics, Techniques, and Procedures (TTPs)
  • New Alerts show previously-dismissed AlertIDs under Notes and Tags

Cause

Previous Alerts were dismissed with Group Alerts turned off

Resolution

  1. From the All Alerts page right-click the Investigate button of the new Alert and open the page in a new tab
  2. Within the URL on the Investigate page, find the threatId tag and copy it

    selected[threatId]={CopyThisTheatID}&

  3. Back on the All Alerts page, search for the ThreatID above (make sure to show Dismissed and Not Dismissed under Workflow on the left)
  4. Turn Group Alerts on
  5. Dismiss the Alert on all devices and check "If this alert occurs in the future, automatically dismiss it from all devices"
  6. Click Dismiss
  7. All Alerts associated with the specified ThreatID will now be dismissed with persistence

Additional Notes

  • Group Alerts must be turned on to dismiss Alerts across multiple devices and with persistence
  • Dismissal is for the specific AlertID (machine specific) and cannot be dismissed for multiple devices when Group Alerts is turned off
  • "If this alert occurs in the future, automatically dismiss it from all devices" has no impact when Group Alerts is turned off

Related Content

Cb Defense: How to Dismiss Alerts

Cb Defense: Alert ID vs. Threat ID

Cb Defense: What Does Dismissing a Group of Alerts do?

Labels (1)
Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎03-13-2018
Views:
869
Contributors