In the Endpoint Security (HX) Web UI, both hosts and alerts in host lists and alert lists may be marked with false positive badges (
).
Note
If a false positive badge has a red circle around the letters "FP" (
), the false positive rule was identified by Trellix. You cannot remove false positive rules identified by Trellix.
If the false positive badge has a black circle around the letters "FP" (
), the false positive rule was added by someone in your organization. These false positive rules can be removed.
When false positive badges are displayed on the Alerts page
Alerts on the Alerts page may be grouped, as described in Understanding alert groups . You can filter your results in the alerts table (for example, by host or by alert type). An alert displays a false positive badge if it matches any of the false positive rules. The false positive badge is applied separately for each unique alert. Using this page you can more accurately separate the malware false positive alerts from the more critical alerts.
When false positive badges are displayed in Host lists
On the Hosts with Alerts tab, hosts display a false positive badge only if all of the alerts for the host are false positive alerts. If the total number of unique IOC (indicator), exploit, and malware alerts matches the total number of unique IOC, exploit, and malware false positive alerts for a host, the false positive badge appears on the line for the host. In addition, this host appears on the Hosts with Alerts tab when it is filtered for False Positive dispositions. If you hover the cursor over the alert count for a host, a tooltip displays the number of each alert type and the number of false positives.
False positive rules may exist for hosts that do not show a false positive badge on the Hosts with Alerts tab, because not every condition that generated an alert for the host matched a false positive rule. A host with false positive alerts but no badge may appear on the Hosts with Alerts tab when it is filtered for Not False Positive dispositions.
To determine if there are any malware false positives for a host, expand the host on the Hosts with Alerts tab to view the alert details on the Host Alert Details page.