Use the Appliance Settings: Suppressed Alerts page to view and manage suppressed alerts on managed Network Security appliances.
When an alert is suppressed, the suppression total is pushed to all managed Network Security appliances. The maximum number of suppressed alerts is 15 for all managed appliances combined. For example, suppose the Central Management System appliance manages a Network Security appliance that already has the maximum number of suppressed alerts.
If you add another Network Security appliance with suppressed MD5s or URLs to the Central Management System appliance, a notice at the top of the page advises you to suppress or resolve alerts until the number is brought down to 15. After you suppress or resolve these extra alerts, the suppressed alerts on the Network Security appliances become out-of-sync. A warning with a link to synchronize them is displayed at the top of the Appliance Settings: Suppressed Alerts page.
Note
For detailed information about the alert suppression feature, see the Network Security User Guide.
Click Settings and then select Appliance Settings.
Click Suppressed Alerts in the sidebar.
Manage the suppressed alerts as described in the Network Security User Guide.
Open the Appliance Settings: Suppressed Alerts page.
A notice at the top of the page advises that too many alerts are suppressed.
Select the checkboxes for the MD5s and URLs with the least impact, and then click Unsuppress or Resolve.
Caution
Do not resolve alerts until the Trellix Security Content team determines that they are false positives and updates its security content. Apply the latest security content update to your appliance, and then resolve the alerts.
Refresh the page. The MD5s and URLs you selected are removed from the page, and a warning at the top of the page informs you about an out-of-sync condition on the managed appliances.
Click the SYNC link in the warning to synchronize alert suppression.