About Alert Policy Exceptions
Alert Policy Exceptions offers system administrators and security analysts a granular, context-aware method to manage the visibility and actionability of individual alerts without modifying central policies or rules.
This feature allows an analyst to dynamically block or unblock alerts based on investigative insights, create specific exceptions that override the default policy for a defined source or destination. This capability is critical for Level 3 analysts who need to reduce noise, prevent unnecessary response actions, or ensure all pertinent alerts are acted upon.
Supported alert category for alert policy exception
Domain-Match
IPSInfection-Match
Local-Signature
Malware-Callback
Reconnaissance
Riskware-callback
Excluded alert category for alert policy exception
Web-infection
Riskware-object
Malware_object
Smartvision-event
Riskware-infection
Access the Alert Policy Exceptions through the Web UI
The Alert Policy Exceptions page displays the list of configured exclusions, allowing you to view, filter, and manage rules that override the standard alert policy. These exceptions ensure specific traffic or conditions are handled differently.
To navigate to the Alert Policy Exceptions page, click
and from INVESTIGATION, select Alert Policy Exceptions.
Note
Before managing alert policy exceptions, ensure that you have already created them from the Alert List page using the Add Alert Policy Exception action. For detailed steps on how to add alert policy exceptions, see Add alert policy exception
View Alert Policy Exceptions
All configured Alert Policy Exceptions on the Alerts list page are displayed in the table. Use the tools available to locate and analyze specific entries.
Table Column | Description |
|---|---|
Created Date | The date and time when the exception was initially created. |
Attacker IP/Mask | The IP address or IP address range identified as the source of the traffic. |
Target IP/Mask | The IP address or IP address range identified as the destination of the traffic. |
Type | The kind of parameter defined for the exception. |
Added By | The user account that created and implemented the policy exception. |
Status | The current operational state of the exception, which states how the policy should be overridden for matching traffic. |
Notes | A text box that typically contains contextual information, justification, or references related to the creation of this specific exception. |
Filter Alert Policy Exceptions
You can apply filters based on criteria such as, the user who Added By the exception or the Status. Use the Filter box above the table to narrow down the exceptions list.
Export Exception lists
For auditing, backup, or migration purposes, you can export the list of exceptions.
Click
and from INVESTIGATION, select Alert Policy Exceptions to navigate to the Alert Policy Exceptions page.Click the Export button.
Select the desired format: CSV or JSON.
Edit Alert Policy Exceptions
You can modify exceptions directly from the Alert Policy Exceptions table.
Click
and from INVESTIGATION, select Alert Policy Exceptions to navigate to the Alert Policy Exceptions page.Select the exception you want to edit, click Actions and then select Edit OR click
beside the exception and select Edit.
Modify the parameters of the exception.
Note
The Attacker IP/Mask and Target IP/Mask fields cannot be modified.
Click Update.
Delete Alert Policy Exceptions
You can delete exceptions to permanently remove them from the list.
Click
and from INVESTIGATION, select Alert Policy Exceptions to navigate to the Alert Policy Exceptions page.Select the exception you want to delete, click Actions and then select Delete OR click
beside the exception and select Delete.