Exclude patterns from learned patterns
Exclude CI-based or CI class-based alerts and patterns when you encounter alerts incorrectly added to a learned pattern by the Learned Patterns job. For example, a pattern might include an alert that occurred at the same time as other alerts but is not actually related to them. This maintains accuracy, ensuring better alert groupings and improved management efficiency.
始める前に
Role required: evt_mgmt_admin
このタスクについて
You select the incorrect alert in a pattern to exclude the entire pattern to which it belongs.
注:
When you exclude an incorrect alert, any other patterns containing that alert are also excluded.
手順
タスクの結果
The entire pattern is removed from the Learned Patterns report and listed on the Excluded Patterns page, located at .
If the pattern includes other alerts, you can restore it by reclaiming those alerts as a learned pattern. For further details, see Restore excluded patterns.