Add a new exceptions security profile
Create Cortex XSIAM exceptions security profiles for legacy endpoint policies.
You can configure exceptions that apply to specific groups of endpoints or you can add a global endpoint policy exception.
Important
Starting with version 1.3, Cortex XSIAM enables you to manage the exception security rules from a central location and easily apply them across multiple profiles in the Legacy Agent Exceptions management page.
To manage the exceptions from Exception Configuration, you must first migrate your existing exceptions configured via the exceptions security profiles.
To create new exception security profile rules using the Legacy Agent Exceptions management page, see Add a legacy exception rule for endpoints.
If you don't migrate the legacy exceptions, you can continue to create exceptions as described below.
How to create an endpoint-specific exception
Add a new profile.
Select the platform to which the profile applies and Exceptions as the profile type.
Click Next.
Define the basic settings.
Select a unique Profile Name to identify the profile. The name can contain only letters, numbers, or spaces, and must be no more than 30 characters. The name will be visible from the list of profiles when you configure a policy rule.
To provide additional context for the purpose or business reason for creating the profile, specify a profile Description. For example, you might include a case identification number or a link to a help desk ticket.
Configure the exceptions profile.
Apply profiles to endpoints.
To remove an exceptions profile, go to the Profiles page, right-click the profile, then select Delete.
Last updated
Was this helpful?
