Removing false positive rules using the Host Details page

Prev Next
To remove a false positive rule using the Host Details page:
  1. Select Hosts at the top of the Endpoint Security (HX) Web UI page.

    The Hosts page appears.

  2. Select the Hosts with Alerts tab.

  3. Click the expand icon (ExpandIcon.png) next to the host with the alert from which you want to remove the false positive rule.

    The Host Alert Details page appears.

  4. Select the alert in the list.

    The rule or indicator that caused the alert is shown at the top of the details pane.

  5. Locate and click the Undo False Positive button.

    • For MAL and XPLT alerts, the Undo False Positive button appears to the right of the rule.

    • For IOC rules, click the Alerted on tab. The Undo False Positive button appears to the right.

    The Undo False Positive page appears.

    HX_FPUndo.png
  6. Optionally, click Export Undo False Positive Alert Details to export the details about the false positive rule removal to a CSV file.

  7. On the Undo False Positive page, click Confirm.

    The false positive rule is removed.

    Note

    You cannot remove part of a false positive rule. If you need to remove a single condition from a false positive rule that includes multiple conditions, remove the whole rule, and then recreate it with only the conditions you need.