From the list of alerts grouped by attack rule name (the Alerts view of the Alerts tab), you can acknowledge all alerts in the entire list, or you can acknowledge alerts on a specific page of the list.
This procedure describes how to use the Alerts view in the Web UI Alerts tab to acknowledge alerts on a specific page.
Requirements
You are logged in to the Web UI as Admin or Analyst.
Procedure
Click the Alerts tab.
Click the Alerts link in the control bar.
Set the Alerts filter in the Filters panel to Hide Acknowledged.
(Optional) Filter or sort the alerts by any column in the list.
Go to the page that lists the alerts you want to acknowledge.
Select one or more check boxes located below the control bar and to the left of the Type column.
Note
Reconnaissance events and brute-force events (detected if IPS is licensed and activated on the Network Security) appear in the IPS tab. You cannot acknowledge these events.
Click the Acknowledge button. The Acknowledge Alert dialog appears.
In the text box, enter a note about the acknowledgment action. Comment text is required.
Click Acknowledge.
The acknowledge alerts are removed from the list, and a confirmation message appears.
(Optional) To view all acknowledged alerts grouped by attack rule name, select Show Acknowledged for the Alerts option in the Filters panel.
To view alert acknowledgment details, see Viewing alert acknowledgment history using the Web UI.