You can review false positive rules that affect an alert from the Alerts or the Hosts page.
To review the false positive rules that affect an individual alert using the Alerts page:
Log in to the Endpoint Security (HX) Web UI.
Select Alerts.
Select False Positive in the Disposition column to filter by false positive alert.
Select an alert with a false positive badge. In the alert details, the false positive information for the alert is shown at the top of the details. If more than one false positive rule affects the alert, you can scroll through them.
To review the false positive rules that affect an individual alert using the Hosts page:
The Host Details page for the host appears.
Log in to the Endpoint Security (HX) Web UI.
Select Hosts.
Select the Hosts with Alerts tab.
Expand (click on the next to) a host with alerts that also has false positive rules. You can identify these hosts on the Hosts with Alerts tab by hovering over the alert count in the host list. The number of each type of alert is shown in a tooltip, as well as the number of malware alerts affected by malware false positive rules.
Select an alert with a false positive badge. In the alert details, the false positive information for the alert is shown at the top of the details. If more than one false positive rule affects the alert, you can scroll through them.