How can we exclude specific alerts from participating in alert grouping or correlation mechanisms?

Deepak Jaisingh
Tera Contributor

We have certain alerts that should remain standalone and not be considered in any type of correlation, including:

  1. Rule-Based Correlation
  2. Tag-Based Correlation
  3. CMDB-Based Correlation
  4. Automated Correlation
  5. Manual Correlation

Is there a recommended approach or configuration to ensure these alerts are completely bypassed from all correlation types?

2 REPLIES 2

Deepak Jaisingh
Tera Contributor

I am trying to understand how this is going to help, can you tell me exactly how we need to achieve this