Skip to main content
corymrussell
New Member
November 25, 2015
Solved

IPS alert white list?

  • November 25, 2015
  • 1 reply
  • 5118 views

IPS is sending copious amounts of alerts for HP.SiteScope.Remote.Code.Execution. I'm curious to know if there is a way to exclude these alerts. We have determined this to be a false report generated from a program required one these handful of machines.

 

Any help would be greatly appreciated.

    Best answer by ede_pfau

    In your IPS sensor, there is one part for filters and one for overrides. If you put a specific signature into the overrides section and set the action to "monitor" then this signature will not be re-evaluated in the filter. In your case, you could "exempt" the signature from blocking.

    1 reply

    ede_pfau
    SuperUser
    ede_pfauAnswer
    SuperUser
    November 25, 2015

    In your IPS sensor, there is one part for filters and one for overrides. If you put a specific signature into the overrides section and set the action to "monitor" then this signature will not be re-evaluated in the filter. In your case, you could "exempt" the signature from blocking.

    corymrussell
    New Member
    November 25, 2015

    Thanks. I must have overlooked adding the filter 60 times.