Defining false positive rules on the Host Details page

Prev Next
To define a false positive rule on the Host Details page:
  1. Select Hosts at the top of the Endpoint Security (HX) Web UI page. The Hosts page appears.

  2. Select the Hosts with Alerts tab.

  3. Click the expand icon (ExpandIcon.png) next to the host with the alert you want to mark as a false positive.

    The Host Alert Details page appears.

    Details are shown on the right side of the page. The rule or indicator that caused the alert is shown at the top.

  4. Select an alert in the list to display details.

    • For MAL and XPLT alerts, the Mark False Positive button appears to the right of the rule.

    • For IOC rules, click the Alerted on tab. The Mark False Positive button appears to the right.

  5. Click Mark as false positive

    The Mark as False Positive page appears for MAL or XPLT alerts.

  6. Configure the rule using the instructions in Marking an alert as a false positive.