Alerts can be deleted in a variety of ways:
You can delete alerts manually.
When an alert ages out, it is deleted automatically. See Alert aging .
When an indicator rule is deleted, all associated alerts are deleted automatically. See Deleting indicator rules.
Alerts deleted in any of these ways no longer appear on the Viewing alerts on the Alerts page or Hosts page, or in other alert counts.
This topic describes how to delete alerts manually using the Endpoint Security (HX) Web UI. You cannot use the CLI to delete alerts.
Admin, Senior Analyst, or Investigator access.
Click Alerts from the Dashboard menu to access the Alerts page.
In the Alerts Table, use the Selection column to select the checkbox next to each alert you want to delete.
Click the Delete button above the table, and select Delete from the menu.
Select Hosts at the top of the page.
The Hosts pageHosts Page appears.
On either the Host With Alerts or All Hosts tabs, click the selection box to the left of a hostname.
From the Actions menu, select Delete alerts.
Click Go, and confirm that you want to delete the alerts for the host.