There may be situations in which you prefer not to see specific alerts. For example, while an incident responder is actively responding to a potential compromise, you may want to suppress further alerts about that compromise.
In Helix Enterprise you can suppress any alerts that match an existing alert’s distinguishers, risk, assignee, origin, or rule name for 1 hour, 12 hours, 24 hours, 2 days, 3 days, 1 week, 2 weeks, or 1 month. To suppress all alerts that meet certain criteria, use the Unique Values menu, shown below.
Note
When an alert is suppressed, only the alert itself is suppressed. The rule that triggered the alert remains active.
You can suppress an individual alert from the Alerts page or from the details page for the alert. You can also suppress multiple alerts at a time, either by selection or grouped by a unique alert distinguisher (risk, assignee, origin, rule name).