If alerts are triggered by valid traffic, you can add a combination of conditions for whitelisting SmartVision alerts.
Prerequisites
To remove a combination of conditions from the alerts whitelist:
View the alerts whitelist.
In this example, the list contains a single entry that combines a SmartVision rule ID and an IPv4 source address block.
hostname (config) # show smartvision alert whitelist SmartVision Alert Whitelist Config Rule Source Prefix Dest Prefix Type 91500002 192.168.4.0/24 - rule-sourceRemove a combination of conditions to the alerts whitelist by using the
no smartvision alert whitelistcommand.This example removes the entry from the SmartVision alerts whitelist:
hostname (config) # no smartvision alert whitelist rule 91500002 source 192.168.4.0/24Verify the change.
hostname # show smartvision alert whitelist SmartVision Alert Whitelist Config Rule Source Prefix Dest Prefix Type