Removing false positive rules using the Alerts page

Prev Next
To remove a false positive rule using the Alerts page:
  1. Select Alerts to access the Alerts page.

  2. Set the value in the Disposition column to False Positive to show only the alerts marked as false positive. You can narrow your results further by filtering on other columns (for example, by alert type). See Viewing alerts for more information.

  3. Locate the alert you want to change.

  4. Select Undo False Positive from the Options menu.

    The Undo False Positive page opens.

  5. Optionally, click Export Undo False Positive Alert Details to export the details about the false positive rule removal to a CSV file.

  6. On the Undo False Positive page, click Undo False Positive.

    The false positive rule is removed.