Adding alert policy exception

Prev Next

You can create alert policy exceptions directly from the Alert list page using the Add Alert Policy Exception action. .

  1. Navigate to the Alert list page.

  2. For the alert you want to create alert policy exception, click Main_menu.png > Add Alert Policy Exception.

  3. In the Add Alert Policy Exception window, configure parameters:

    1. From the Action drop-down list, select Block.

      Note

      The action options appears only for supported alert category. To know more about the supported alert categories for alert policy exceptions, see Manage Alert Policy Exceptions.

    2. From the Signature drop-down list, select the appropriate options. By default signature ID is selected. You can choose options based on your requrement.

    3. In the Attacker IP/Mask the values are displayed by default and cannot be edited.

    4. In the Target IP/Mask the values are displayed by default and cannot be edited.

    5. In the Expires On field, select the date for the policy exception to be expired.

    6. (Optional) Add a note in the Note field to provide additional context for the policy exception.

    7. Click Add to create the alert policy exception.

Note

After creating alert policy exception on the NDR, if there is any match detected on NDR Sensor, Block/Unblock action overides the default actions.

You can view and manage all alert policy exceptions created from the NDR on the Alert Policy Exception page.