IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Managed Detection: How to Remove Repeat Results From Trusted Processes/Files

Managed Detection: How to Remove Repeat Results From Trusted Processes/Files

Environment

  • Carbon Black Cloud Console: All versions
  • Managed Detection Reports

Objective

How do I remove repeated results in ThreatSight Reports for trusted processes? 

Resolution

The values in the ThreatSight Reports are based on the Alerts ThreatSight uses for the data. By setting dismissals for Grouped Alerts in the future and possible Policy Permissions to filter out these Alerts they will not show in the ThreatSight Reports. 

Additional Notes

Using Grouped Alerts for future dismissal is the best way to filter out the trusted applications not being Terminated by the Policy Rules. This still logs all the information but helps seeing the significant Events / Processes easier for review. 

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-20-2019
Views:
488
Contributors