Skip to main content
The Tier4 platform automatically extracts relevant rules that triggered each alert across the full range of security products. The Rule Insights page aggregates counts for rules that triggered false positives in the environment. This aggregated view provides insight into the products, and rules specifically, that are causing the greatest amount of noise and could use tuning. Tuning these noisy rules helps reduce the volume of alerts in your security systems as well as reduce the volume of alerts processed by Tier4.

Exclusions

To see indicators associated with a noisy rule, click the indicator to open a drawer highlighting the top correlations. Selecting the toggle will turn on an exclusion policy in Tier4 for the combination of the rule and indicator. In the future, if this combination is seen, the alert will be routed to a separate pathway to process as a benign behavior. Exclusions can be removed at any time by navigating to the exclusions tab and clicking the trash can icon.
Exclusions should only be used in situations where the behavior being flagged is ALWAYS a false positive. For example, you have a vulnerability scan that runs via a administrative account on a periodic basis. Once an exclusion is entered, every alert with that combination will be flagged as a false positive. We recommend first tuning the point solution (EDR, IDP, Email) before adding exclusions in the Tier4 platform as you will have more control over the finer details on the exclusion.