Manually delete custom indicator rules using the Web UI

Prev Next

Indicator rules can be removed in a variety of ways:

  • You can manually delete custom indicator rules.

  • Indicator rules can be automatically deleted (or aged). See Indicator rule aging .

Note

When an indicator rule is deleted, all associated alerts are automatically deleted.

This topic describes how to manually delete custom indicator rules using the Endpoint Security (HX) Web UI. You cannot use the CLI to delete indicator rules.

Prerequisites
  • Administrator, Senior Analyst, or Investigator access.

To manually delete custom indicator rules using the Web UI:
  1. Select Rules from the Configure section of the main menu. The Rules page appears.

  2. On the Indicators tab, in the Indicators grid, select the checkbox to the left of the indicator rule that you want to delete.

  3. In the Actions list, click Delete indicator, and then click Go.

    The custom indicator rule is deleted.