Adding Exclusions to Rules
Adding Exclusions to a Specific Rule
Adding Global Exclusions
- Go to Policy > Threat Prevention > Global Exclusions.
- Expand an exclusion category. For example, Anti-Bot -> URL Filtering Exclusions.
- Select the exclusions you want to add to the rule.
- Click Save.
- From the top, click Install Policy.
Adding Exclusions from Security Overview
-
You cannot add exclusions for Forensic events triggered by Anti-Bot.
-
You cannot add exclusions for Forensic events triggered by Anti-Malware engine that has no reference event.
-
This procedure is not supported for macOS endpoints.
To add exclusions from Security Overview:
- Go to Overview > Security Overview.
- Right-click the security event and select Drill Down.
- Right-click the event and select one of these options.
-
Create Exclusion for Effective Rule
The Edit Exclusions Center window appears and automatically adds the exclusion.
-
Create Exclusion for All Rules
-
If Global Exclusions is not enabled, the Edit Exclusions Center window opens and automatically adds the exclusion to all the rules under Policy Capabilities.
-
If Global Exclusions is enabled, the Edit Exclusions Center window opens and automatically adds the exclusion to Global Exclusions. For more information, see Adding Global Exclusions.
-
-
- Click OK.
- Click Save for all the modified policies.
- Click Install Policy.
Adding Exclusions from Logs
To add exclusions from the Logs menu:
- Go to Logs menu.
- Right-click a log to add and configure an exclusion to your endpoint device. This redirects you to the appropriate rule, section, and capability.
- Select one of these options to apply the exclusions.
-
Effective option: For a specific device or a user rule.
-
All options: For a specific rule.
-
-
This option is available only for Endpoint Security client version 86.20 and later.
-
For Endpoint Security client version 86.20 or earlier, or for unsupported blades/capabilities, you are redirected to the relevant rule in the exclusions center to create exclusions.
Adding a New Exclusion to an Exclusion Category
-
-
Go to Policy > Threat Prevention > Policy Capabilities.
-
Go to Policy > Threat Prevention > Global Exclusions.
The Edit Exclusions Center window appears.
-
-
Click
. The New Exclusion window appears.
- Specify these details.
-
Exclusion
-
Method
-
Value
-
(Optional) Comment
-
To add the exclusion to all the rules, select the Add to all rules checkbox. This step does not apply to Global Exclusions.
Note:If the current rule contains this exception, then the system adds a duplicate exclusion.
-
- Click OK.
- In the bottom right corner of the policy configuration pane, click Save.
- From the top, click Install Policy.
Editing an Exclusion
-
Do one of these:
-
Go to Policy > Threat Prevention > Policy Capabilities.
-
Go to Policy > Threat Prevention > Global Exclusions.
The Edit Exclusions Center window opens.
-
-
Expand an exclusion category. For example, Anti-Bot -> URL Filtering Exclusions.
-
If you are editing a local exclusion, expand Local Exclusions. This step does not apply to Global Exclusions.
-
Select the exclusion you want to edit.
-
Click
.
The Edit Exclusion window appears.
- Specify these details:
- Exclusion
- Method
- Value
- (Optional) Comment
- To apply the changes to all the rules that contain this exclusion, select the Update all rules checkbox. This step does not apply to Global Exclusions.
- To add the exclusion to all the rules that does not contain this exclusion, select the Add to all rules checkbox. This step does not apply to Global Exclusions.
- Click OK.
- In the bottom right corner of the policy configuration pane, click Save.
- From the top, click Install Policy.