To eliminate all data exfiltration alerts (but not other types of SmartVision alerts) triggered by data uploads to a particular destination, you can whitelist the destination host or network.
If data exfiltration activity is detected, the appliance normally generates a Data Exfiltration SmartVision alert and logs the event in the SmartVision database. However, no data exfiltration alert is generated if either of the following conditions is true:
The event matches a condition in the SmartVision alerts whitelist.
The event destination host or network IP address is listed in the data exfiltration alerts whitelist. You cannot filter data exfiltration alerts on source IP addresses.
Data exfiltration alert whitelisting does not support IPv6 addresses.
Note
SmartVision maintains two whitelists. The SmartVision alerts whitelist applies to all post-exploitation attacker events, including data exfiltration events. The data exfiltration detection whitelist applies to data exfiltration events only.