Anomaly Exceptions
Anomaly Exceptions identify expected behavior that should be excluded from normal behavioral anomaly results. Events remain available for investigation.
Open Detect > Behavioral Analytics > Anomaly Exceptions. Operator or Admin permission is required to manage exceptions.
What an exception changes
- Matching anomaly records are hidden from the default anomaly view.
- Event collection continues.
- Existing alerts are not deleted or automatically resolved.
- Runtime blocking policies remain active.
- Other alert rules and attack chains have their own controls.
Use Show suppressed in Behavioral Analytics to review excluded anomaly records.
Create an exception
- Select Create exception.
- Enter a descriptive name and the reason for the exception.
- Select the target sensor, or use the available broader scope only when appropriate.
- Choose an event kind and executable pattern.
- Set an expiry for temporary activity.
- Review the scope and save.
Use the full executable path when possible. An exact path matches that executable; * matches part of a path. For example, /usr/bin/chronyd identifies one executable and */chronyd matches that name in different directories.
Avoid a fleet-wide wildcard when the expected behavior belongs to one application on one host.
Review and remove exceptions
Search the exception list by name, pattern, or reason. Review the target, expiry, and recent matches when available.
Delete an exception when the activity is no longer expected. Expiry or deletion stops it from excluding new matching activity; previously suppressed records are not rewritten.
From an alert
Suppress similar creates an anomaly exception using the available alert context. Review its pattern and scope before confirming. It does not silence all future alerts with similar wording.
Reopening the alert does not remove the exception. Manage it separately under Anomaly Exceptions.
Attack-chain decisions
To dismiss an individual attack-chain match, open Detect > Attack Chains and select False Positive - Suppress. Use All to include suppressed matches and Re-activate to restore a match.
This is separate from a reusable anomaly exception.
Review checklist
- Does the exception apply only to the intended application and sensors?
- Is the reason still valid?
- Should a temporary exception expire?
- Has a workload change made the pattern obsolete?
- Does suppressed evidence still need investigation?