Creating Alert Exclusion Filters

Alert filters ignore events that you're not interested in. The filtered alerts do not appear in the Alert index. You can create them from the System | Machine Learning| Exclusions menu or from the Event details.

Creating an Alert Filter from the System Menu

To create an Alert Filter from the System menu:

  1. Click System | Machine Learning | Exclusions. The Alert Filters table appears.
  2. Click the Create button. The Add an Alert Filter screen appears.

  3. Enter a Name. The name cannot be changed after you submit.
  4. Select a Tenant.
  5. Define your condition. Click Add Condition. You can add as many conditions as you like. If an event meets any condition it is ignored. In our example we are ignoring all events generated by the destination IP address 192.168.229.153.
  6. (Optional) Add a Note.
  7. Click Submit. The filter is immediately added.

Creating an Alert Filter from the Event Display

To create an Alert Filter from the event display:

  1. Click More Info for an event.
  2. Click the Actions tab.
  3. Click the Add an Alert Filter button. The Add an Alert Filter screen appears with fields pre-populated based on the selected event.

  4. Enter a Name. The name cannot be changed after you submit.
  5. Select a Tenant.
  6. Define your condition. Click Add Condition. You can add as many conditions as you like. If an event meets any condition it is ignored. In our example we are ignoring all bad_process alerts from 192.168.100.92. These fields were pre-populated from the event display's data.
  7. (Optional) Add a Note.
  8. Click Submit. The filter is immediately added.

Adding a Boolean Filter

You can add a condition that contains a Boolean field.

  1. Click Add Condition.

  2. For Field, enter or select a Boolean field name.

  3. For Field Type, choose boolean.

  4. Choose an Operator.

  5. For Value, choose either true or false.

  6. Click Submit.