At times, to handle falsely flagged events, administrators may need to create exceptions for anomaly detections.
-
Go to Events screen.
-
Select the anomaly event for which you want to create an exception.
-
Click on the vertical ellipsis icon (in the right side of the selected anomaly event), and then select Add Exception.
Create allow-list for anomaly pop-up screen appears.
-
Under Allow-List type, select the required exception from the drop-down.
Note:
The drop-down shows different options applicable for the anomaly event you selected.
-
Under Apply for all past events, select Yes or No.
-
If required, enter a Comment for the anomaly exception.
-
Click OK.
To see all the anomaly exceptions, go to Security Settings > Exceptions > Anomaly.