From the list of alerts grouped by attack rule name (the Alerts view of the Alerts tab), you can view a list of acknowledged alerts and clear those acknowledgments.
You can clear acknowledgments of all alerts in the entire list, or you can clear acknowledgments from a specific page of the list. This procedure describes how to use the Alerts view in the Web UI Alerts tab to clear acknowledgments of all retrieved alerts in the entire list.
Requirements
You are logged in to the Web UI as Admin or Analyst.
Procedure
Click the Alerts tab.
Click the Alerts link in the control bar.
Select Filter > Alerts > Show Acknowledged.
Select the top check box located below the control bar and to the left of the Type column.
Every acknowledged alert in the current page only is selected.
Note
Reconnaissance events and brute-force events (detected if IPS is licensed and activated on the Network Security) appear in the IPS tab. You cannot acknowledge these events.
To unacknowledge all alerts on all pages, click the SELECT ALL ALERTS button. If you go to any other page, all acknowledged alerts are selected.
Click the Unacknowledge button. The Unacknowledge Alert dialog appears.
In the text box, enter a note about the acknowledgment action. Comment text is required.
Click Unacknowledge.
The cleared acknowledgments are removed from the list, and the following message appears: