CloudGuard Dome9 Help
You can exclude specific findings from appearing in the results of assessments, for both manually triggered compliance assessments, and continuous compliance assessments.
Using exclusions, you can declutter the findings lists by removing findings that are not interesting to you. The excluded findings will also not be included in the calculation of the overall assessment results, or the results for a specific rule. Excluded findings will also not be sent as notification messages (by email, SNS, etc) to external systems.
Some typical cases to use exclusions include:
- exclude findings from irrelevant rules, for a specific cloud account or for all cloud accounts, for example when using predefined Dome9 rulesets, when some rules are not applicable to your environment
- replace a rule that requires customization
- stop generating findings for a specific entity, if a rule is irrelevant for the entity
You can exclude alerts from specific rules and bundles from generating findings. These are exclusions. Use them to declutter the findings lists for both manually triggered assessments and continuous compliance assessments.
Navigate to the Exclusions page in the Compliance & Governance menu.
Click Create New Exclusion, in the upper right.
- Select the Ruleset to exclude, from the list.
- Select the type of exclusion:
- Exclude by Rule - exclude a specific rule. Select the rule from the drop-down list (which opens when this option is selected). If not checked, all rules are excluded.
- Exclude by Cloud Account - exclude a specific account. Select the account from the drop-down list. If not checked, all accounts are excluded.
- Exclude by Entity - exclude specific entities. Enter the entity name or ID. You can include the wildcard '%' in the entity name, to include a group of entities. For example, '%s3% matches all entities with 's3' in their name, all of which would be included in the exclusion.
- Click Exclude.
- Navigate to the Exclusions page in the Compliance & Governance menu.
- Hover over the exclusion that you wish to delete, and then click .