Exclusion lists allow you to define fields that rules will ignore. This means the rule will not trigger if the defined field appears in the incoming event. For example, you want to create a rule that doesn't generate an alert if the incoming event has the source IP address 1.1.1.1. You can create a list containing the IP address 1.1.1.1 and add the list to your rule.
Using detection rule exclusions to create an allowed list
- Updated on Sep 13, 2026
- Published on Sep 12, 2026
- 1 minute(s) read
Was this article helpful?