Endpoint Protection

 View Only
  • 1.  Possibly to mute "attacks" from one ip address?

    Posted Mar 19, 2020 10:13 AM
    Someone's doing scans from another area of my org.  That's ok, but it's blowing up my SEPM logs and alerts.  Is there any way to "mute" attacks from a certain ip address?


  • 2.  RE: Possibly to mute "attacks" from one ip address?

    Posted Apr 02, 2020 03:22 AM
    If you know who is doing these scans (for example if they are authorized Vulnerability scans) then you can exclude the IP address in the Intrusion Prevention Policy -> Excluded hosts.