You can add an attack to the policy of an admin domain. This depends on the admin domain from where the alert was generated. When an attack is added to the policy, the policy specific to that admin domain is updated. The attack is added to the selected policy set. To add the attack to the policy:
Steps:
Navigate to Analysis → <Admin Domain Name> → Attack Log.
Select the alert, click Other Actions at the bottom of the page.
Select Update Policy, and click (Domain IPS) /<Admin Domain Name>/<Policy Name>.
The <Attack Name> panel opens.
Make the required changes to the policy settings and click Update.
The attack is added to the selected policy set.
To view/edit the attack added to the policy:
Navigate to Policy → <Admin Domain Name> → Intrusion Prevention → Policy Types → IPS.
Double-click the policy.
You can view the attack added to the list under the Attack Definitions tab.