You acknowledge alerts to indicate that the events have been reviewed and do not require immediate resolution. By default, acknowledged alerts are hidden, enabling you to more easily identify the alerts that still need to be reviewed and resolved.
The Alerts view of the Alerts tab lists alerts grouped by attack rule name. Multiple alerts associated with the same signature rule are combined in a single entry in the list. From the Alerts view, you can acknowledge all events in the entire list, or you can acknowledge events in a single page of the list.
Note
Reconnaissance events and brute-force events (detected if IPS is licensed and activated on the Network Security) appear in the IPS tab. You cannot acknowledge these events.
To acknowledge alerts in the Alerts view, select the alerts to be acknowledged and enter a reason for the acknowledgment. To clear alert acknowledgments, select the acknowledged alerts and enter a reason for clearing the acknowledgments.
From the Hosts view of the Alerts tab, you can view the acknowledgment history for alerts for a host IP address. You can also edit the comments for alert acknowledgment actions.
Note
Before you select the alerts you want to acknowledge, you can filter and sort the alerts in the list. For more information, see Filtering Alerts and Events Using the Web UI.