Environment
- Carbon Black Cloud Console: All Versions
Question
What happens when an Alert is dismissed with Group Alerts on?
Answer
When Group Alerts is turned on, all Events associated with that ThreatID are dismissed.
Additional Notes
- If all future instances are dismissed, only those with the same ThreatID will be dismissed.
- The analytics engine builds an identifier or "cause" called a ThreatID based on factors including both the application and the behavior of the application.
- Threats with the same "cause" are grouped together on the Alerts pages (All Alerts, Preventions, Detections).
- It will not dismiss any other actions done by the same file unless they are also tied to the same ThreatID.
Related Content