Environment
- EDR (Formerly CB Response) Console: All Supported Versions
Objective
How to Ignore Future Events for False Positive Alerts
Resolution
- In the navigation bar, select Triage Alerts.
- In the Alerts table, select the check box to the left of the alert with the triggering event to ignore.
- Click the False Positive button
- In the "Mark All as Resolved False Positive" window, future events can be ignored from this report by moving the slider button to Yes.
- To resolve the alert and ignore future events, click the Resolve button.
Additional Notes
- Marking events from multiple alerts to be ignored involves searching for the alerts to ignore, confirming that the results that are expected, and then making a bulk resolution.
- Do note that only threat feed alerts can be designated as alerts to ignore. Alerts from watchlist matches are always triggered, since watchlists are assumed to use criteria specifically chosen.
Related Content