Exclusion Lists are pre-defined lists of exclusions that can be quickly applied to your data to remove known false positives. These lists can be customized to fit your specific needs and can be updated as necessary to ensure ongoing accuracy.
The Exclusion Lists within Mobula can be found by navigating to the following path: /All Active Lists/Mobula Exclusion Lists, Or from rule condition. Once you've located the necessary Exclusion Lists, you can further refine your settings by following the same path as the Rule Path. This will allow you to easily manage your exclusions and ensure that your monitoring settings are optimized for your specific needs. By using Exclusion Lists in conjunction with Mobula's comprehensive content, you can achieve a finely tuned security monitoring system that provides optimal protection for your network.
Click on the alert to review it.
On the top side of the window you will see Exclusions option
3. Click on Exclusions.
4. Choose which field/s you want to exclude from specific alerts so they won't trigger again.
We suggest writing down a comment so that you can read it later and remember why you did it.
5. Check that the exclusion Field gives you the specific value that you want to exclude.
6. Click Save.
7. If you don't see an exclusion option that you want to exclude/or the fields are incorrect, just click on ”Report a feedback” and write down what you want to add. We will check and reply to you with an answer as soon as possible.
First log into the Mobula application
Open the options menu and find “Active Rules”.
Search for the rule by name you want to add a manual exclusion
(For example, we will search for the “Egress Restricted Services Communication Passed by Firewall” Rule)
6. Here, you can choose the option that is suitable for you.
(Note: each alert will have its own exclusion options)
7. If you don't see an exclusion option that suits you, skip to the “Ask for new Exclusions options” section.
8. If you made an exclusion for the customer, send an email to inform him about it.