To eliminate all SmartVision alerts (including data exfiltration alerts) triggered by a particular combination of SmartVision rule ID, traffic source, and traffic destination, you can create an entry in the SmartVision alerts whitelist.
An entry in the whitelist specifies one or more of the following event-matching conditions:
Rule ID—The ID of a SmartVision rule that generates unwanted alerts.
Source IP address—The sender of valid traffic that triggers unwanted SmartVision alerts.
Destination IP address—The receiver of valid traffic that triggers unwanted SmartVision alerts.
The SmartVision alerts whitelist is empty by default.
If a SmartVision event is detected but the event matches all the conditions specified by any entry in the SmartVision alerts whitelist, no SmartVision alert is generated and no events are logged in the SmartVision database.
For information about the data exfiltration alerts whitelist, see Managing noisy data exfiltration alerts.