Manage Alert Policy Exceptions

Prev Next

About Alert Policy Exceptions

Alert Policy Exceptions offers system administrators and security analysts a granular, context-aware method to manage the visibility and actionability of individual alerts without modifying central policies or rules.

This feature allows an analyst to dynamically block or unblock alerts based on investigative insights, create specific exceptions that override the default policy for a defined source or destination. This capability is critical for Level 3 analysts who need to reduce noise, prevent unnecessary response actions, or ensure all pertinent alerts are acted upon.

Supported alert category for alert policy exception

  • Domain-Match   

  • IPSInfection-Match

  • Local-Signature

  • Malware-Callback

  • Reconnaissance

  • Riskware-callback

Excluded alert category for alert policy exception

  • Web-infection

  • Riskware-object

  • Malware_object

  • Smartvision-event

  • Riskware-infection

Access the Alert Policy Exceptions through the Web UI

The Alert Policy Exceptions page displays the list of configured exclusions, allowing you to view, filter, and manage rules that override the standard alert policy. These exceptions ensure specific traffic or conditions are handled differently.

To navigate to the Alert Policy Exceptions page, click Main_menu.png and from INVESTIGATION, select Alert Policy Exceptions.

Note

Before managing alert policy exceptions, ensure that you have already created them from the Alert List page using the Add Alert Policy Exception action. For detailed steps on how to add alert policy exceptions, see Add alert policy exception

View Alert Policy Exceptions

All configured Alert Policy Exceptions on the Alerts list page are displayed in the table. Use the tools available to locate and analyze specific entries.

Table Column

Description

Created Date

The date and time when the exception was initially created.

Attacker IP/Mask

The IP address or IP address range identified as the source of the traffic.

Target IP/Mask

The IP address or IP address range identified as the destination of the traffic.

Type

The kind of parameter defined for the exception.

Added By

The user account that created and implemented the policy exception.

Status

The current operational state of the exception, which states how the policy should be overridden for matching traffic.

Notes

A text box that typically contains contextual information, justification, or references related to the creation of this specific exception.

Filter Alert Policy Exceptions

You can apply filters based on criteria such as, the user who Added By the exception or the Status. Use the Filter box above the table to narrow down the exceptions list.

Export Exception lists

For auditing, backup, or migration purposes, you can export the list of exceptions.

  1. Click Main_menu.png and from INVESTIGATION, select Alert Policy Exceptions to navigate to the Alert Policy Exceptions page.

  2. Click the Export button.

  3. Select the desired format: CSV or JSON.

Edit Alert Policy Exceptions

You can modify exceptions directly from the Alert Policy Exceptions table.

  1. Click Main_menu.png and from INVESTIGATION, select Alert Policy Exceptions to navigate to the Alert Policy Exceptions page.

  2. Select the exception you want to edit, click Actions and then select Edit OR click Browse_icon.JPG  beside the exception and select Edit.

  3. Modify the parameters of the exception.

    Note

    The Attacker IP/Mask and Target IP/Mask fields cannot be modified.

  4. Click Update.

Delete Alert Policy Exceptions

You can delete exceptions to permanently remove them from the list.

  1. Click Main_menu.png and from INVESTIGATION, select Alert Policy Exceptions to navigate to the Alert Policy Exceptions page.

  2. Select the exception you want to delete, click Actions and then select Delete OR click Browse_icon.JPG  beside the exception and select Delete.