View Categories

Alert Rules – Report False Positives

Table of Contents

Due to anomalies that may occur we added an advancement to our Alert Rules in GAT Shield.

Now Admins/Auditors can investigate Shield Alerts and where an instance of anomaly occurs they can mark the Shield Alert as a “false positive“. This will help advance the quality of alerts triggered and help us track and tackle any anomalies that may occur.

To utilise this feature, navigate to your GAT Shield Alerts section.

Shield Alerts #

Navigate to Shield -> Alerts -> Notifications and inspect an alert by selecting the ‘Details‘ icon displayed when hovering the cursor over the right side of the record.

An Alert Notification Admin/Auditor can perform the following actions:

  • Acknowledge – the auditor can Acknowledge  the alert – marking it as “acknowledged” – meaning is checked and acknowledged
  • Update Severity – either increase or reset severity level, acknowledge the seriousness of the alert  based on an impact it may have on your domain
  • See the alert notification Details – view details for the Alert notification triggered.

Alert notification action buttons: Acknowledge button, increase or reset Severity button, view more Details button.

When Details are selected, a new window will be displayed with all the additional details for the Alert rule

  • Acknowledge – on the top left side you can acknowledge the Alert
  • Update Severity – Marks this alert as either High or Low. This will be used by an algorithm later on.
  • Review Next alert – move on to the next alert

Alert Notifications Details window displaying Acknowledge button, Severity button and Next alert button to be able to move on and review the next alert notification.

  • Report false positive – notify us about false-positive alert – click on 3 dots (1) and “Report false positive” (2)

Alert Notifications Details window displaying Report false positive option. To report false positive alert, click on 3 dots next to "Next alert" button (1), click on Report false positive button displayed to create the report.

A new window will appear where you can add an appropriate support message to explain why the alert was identified as a “false positive” (1). To send the message to us, click Send button (2).

The Report False Positive dialog box is displayed, where you can type a Support team message to inform the appropriate team about generated a false positive alert.

Alert and rule related details will be sent internally. Please leave short explanation why alert works incorrectly. We will review it as soon as possible. Describe what the expected result was.

Result #

We will receive your message, investigate it and get back to you promptly.

LIVE EVENT

Join Us for a Training Session

For customers and current trials.

This website uses cookies to ensure you get the best experience on our website