IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to Ignore Future Events for False Positive Alerts

EDR: How to Ignore Future Events for False Positive Alerts

Environment

  • EDR (Formerly CB Response) Console: All Supported Versions

Objective

How to Ignore Future Events for False Positive Alerts

Resolution

  1. In the navigation bar, select Triage Alerts.
  2. In the Alerts table, select the check box to the left of the alert with the triggering event to ignore.
  3. Click the False Positive button
  4. In the "Mark All as Resolved False Positive" window, future events can be ignored from this report by moving the slider button to Yes.
  5. To resolve the alert and ignore future events, click the Resolve button.

Additional Notes

  • Marking events from multiple alerts to be ignored involves searching for the alerts to ignore, confirming that the results that are expected, and then making a bulk resolution.
  • Do note that only threat feed alerts can be designated as alerts to ignore. Alerts from watchlist matches are always triggered, since watchlists are assumed to use criteria specifically chosen.
     

Related Content


Labels (2)
Tags (3)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-18-2020
Views:
1174
Contributors