From the list of alerts grouped by attack rule name (the Alerts view of the Alerts tab), you can clear all alert acknowledgments in the entire list, or you can clear selected alert acknowledgments on a specific page of the list.
This procedure describes how to use the Alerts view in the Web UI Alerts tab to clear selected alert acknowledgments on a specific page of the list.
Requirements
You are logged in to the Web UI as Admin or Analyst.
Procedure
Click the Alerts tab.
Click the Alerts link in the control bar.
Select Show Acknowledged in the Filters panel.
(Optional) Filter or sort the alerts by any column in the list.
Go to the page that lists the alert acknowledgments you want to clear.
Select one or more check boxes below the control bar and to the left of the Alert Type column.
Note
Reconnaissance events and brute-force events (detected if IPS is licensed and activated on the Network Security) appear in the IPS tab. You cannot acknowledge these events.
Click the Unacknowledge button. The Unacknowledge Alert dialog appears.
In the text box, enter a note about the acknowledgment action. Comment text is required.
Click Unacknowledge.
The cleared acknowledgments are removed from the list, and a confirmation message appears.
To view all alerts grouped by attack rule name, select Allfor the Alerts option in the Filters panel.