You can mark an alert as a false positive on the Alerts page. This creates a false positive rule that is then applied to other alerts matching the same criteria. To learn more about marking an alert as false positive from the Alerts page, see Marking an alert as a false positive.
Endpoint Detection and Response with Forensics (EDRF) > Detect and handle potential threats with EDRF > Configure EDRF to detect potential threats > Managing alerts, quarantined files, and false positives