- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-27-2024 01:33 AM
Hi is there any specific guidance or information relating to how long it can take to apply 'auto-resolve' after creating an Alert Exclusion filter rule using XSIAM > Exceptions > Alert Exclusions when using the setting 'Apply rule On Existing Alerts' ?
06-27-2024 04:58 AM - edited 06-27-2024 10:23 PM
Hello, @john-lillington nystateofhealth
When you create an Alert Exclusion filter rule in XSIAM using the setting 'Apply rule On Existing Alerts', the time it takes for the 'auto-resolve' to apply can vary depending on several factors, including the number of existing alerts and the system's current load. Generally, this process should be relatively quick, often completing within minutes, but for a large volume of alerts, it might take longer. If you experience significant delays, it might be helpful to consult XSIAM documentation or contact support for more specific guidance.
I hope this will help you
Best regards
chris wright
06-27-2024 04:58 AM - edited 06-27-2024 10:23 PM
Hello, @john-lillington nystateofhealth
When you create an Alert Exclusion filter rule in XSIAM using the setting 'Apply rule On Existing Alerts', the time it takes for the 'auto-resolve' to apply can vary depending on several factors, including the number of existing alerts and the system's current load. Generally, this process should be relatively quick, often completing within minutes, but for a large volume of alerts, it might take longer. If you experience significant delays, it might be helpful to consult XSIAM documentation or contact support for more specific guidance.
I hope this will help you
Best regards
chris wright
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!