Reviewing all false positive rules

Prev Next

You can review all false positive rules on the False Positives tab of the Rules page.

To review all the false positive rules in your Endpoint Security environment using the Web UI:
  1. Log in to the Endpoint Security (HX) Web UI.

  2. Select Rules to access the Rules page.

  3. Select the False Positives tab.

    The False Positives tab lists all of the false positive rules defined in your environment.

    FP_RulesList.png
  4. To export the false positive rule details, click Export False Positive Alert Details in the Detail pane.

Duplicate malware false positive rules may appear on the False Positives tab of the Rules page. These duplicates may show different affected host counts in the Rule Details area of the False Positives tab. Duplicates can occur when Trellix adds a malware false positive rule specific to one scan type that matches a false positive rule created by the user that applies to all malware scan types. But if the malware scan for a particular malware scan type has not been run, the affected host counts (in the False Positives Detail area) for that scan type will be zero for that rule. Non-zero host counts are only shown for scan types that actually ran and that generated an alert for the rule before it was marked false positive.

The types of on-demand malware scans that can be run are full scan, memory scan, and custom scan. The only type of on-access scan that runs is the real-time scan.