This topic describes how to suppress MD5s and URLs that are attached to alerts that you suspect or know are false positives. (See Alert suppression for an overview of this feature.)
Important
You can suppress a total of 15 MD5s and URLs combined. If you suppress both the MD5 and the URL that are attached to a single alert, it counts as two against the maximum of 15. If multiple appliances or sensors are managed by a Central Management System appliance, the maximum number for the whole system is 15.
You can suppress only a child alert for a ZIP file. The Suppress This Alert link does not appear if you attempt to suppress a parent alert for a ZIP file.
Log in to the Web UI as a user with the Admin or Analyst role.
Click the Alerts tab to open the Alerts page.
Click the Alerts link at the top of the page to view the list of alerts.
Click the event under Alert Type that you want to suppress. (You can suppress alerts with the alert type of Web Infection or Malware Object.)
The alerts associated with the MD5s and URLs you suppressed are no longer displayed on the Alerts page, and the Total number at the top of the page is reduced by the number of alerts matching the MD5s or URLs being suppressed. The reduced numbers are also reflected in the show alert summary CLI command output. (For details about the command, see the TrellixCLI Reference.)
Note
It could take a few minutes for alert suppression to take effect.
For information about viewing and managing suppressed MD5s and URLs, see Managing suppressed alerts.