For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Exclude an alert

You can exclude alerts that are not deemed to be a threat.

Notice

This functionality requires a Cortex XDR Pro license.

During the process of triaging and investigating alerts, you might determine that an alert does not indicate threat. You can choose to exclude the alert, which hides the alert, excludes it from incidents, and excludes it from search query results.

You can also set up alert exclusion rules that automatically exclude alerts that match certain criteria. For more information, see Alert exclusions.

Note

Cortex XDR supports exclusion of up-to 100,000 alerts.

How to exclude an alert

  1. From the Alerts page, locate the alert you want to exclude.

  2. Right-click the row, and select Manage Alert → Exclude Alert.

    A notification displays indicating the exclusion is in progress.

Last updated

Was this helpful?