icon-zwp.svg
Posture Control (ZPC)

Adding Alert Ignore Filters

ZPC triggers alerts for all the security violations and vulnerabilities that are detected in your cloud resources. You can set up filters to ignore specific alerts that you don't want to be notified about or you don't want to take any action. To learn more, see Ignore Filters.

  • The ignore filters are applied only to the newly triggered alerts.
  • By default, users with admin and security operations (SecOps) role can add ignore filters. All other ZPC users have view-only permission. You can enable the add permission to other ZPC users by adding or modifying Ignore Rules permissions in Global Modules. To learn more, see Adding a Custom Role and Editing or Deleting a Custom Role.

To add ignore filters:

  1. In the left-side navigation, select Alerts.
  2. On the Alerts page, click the Ignore Filters tab.
  3. Click + Ignore Filter.

  1. On the General Information page:
  • Type of Alerts: Select Cloud or IaC.
  • Ignore Filter Name: Enter a unique name for the filter.
  • Filter Description (Optional): Enter a description.
  • Ignore Filter End Date: Select the duration for which you want to snooze the alert. This filter is disabled after the end date and alerts are triggered for security policy violations.

  1. Click Next.
  2. On the Filter Scope page:
    • For Cloud Alerts, select at least one of the filters below:
        • All Policies: The filter applies to all policies.
        • Theme: Select the required Policy Theme from the drop-down menu (Compliance, Security Events, Security Exposure, and Blank).
        • Category: Select the required Threat Category from the drop-down menu.
        • Severity: Select the required Policy Severity from the drop-down menu.
        • Select Policies: Select to view the Select Existing Policies page, and select the required policies from the table.

          To learn more, see About Security Policies.

        • Policy Focus: Select Asset or Identity from the Policy Focus drop-down menu.

        By default, the All Policies filter is selected.

        Close
      • Select the cloud account, business unit, or provider. Depending on your selection, one of the following additional fields displays:
        • Select Accounts: Select the required cloud accounts that must be included in the filter.
        • Business Units: Select the required business units that must be included in the filter.
        • Cloud: Select the cloud provider (AWS, Azure, GCP, or Kubernetes). For Kubernetes, select the required Cluster Names and Namespaces from the drop-down menu.

        By default, the All Accounts filter is selected.

        Close
      • Select from a list of cluster names.

        By default, the All Kubernetes Clusters filter is selected.

        Close
      • Select from a list of namespaces.

        By default, the All Kubernetes Namespaces filter is selected.

        If you don't have any onboarded Kubernetes clusters, then the Cluster Names and Namespaces fields are not displayed.

        Close
      • Click the Tags drop-drown menu and choose Select Tags. Click the Add Tags icon that appears, to include the required tags.

        By default, the All Tags filter is selected.

        Close
        • All Assets: The filter applies to all assets.
        • Asset Type: Select the required Asset Type from the drop-down menu.
        • Asset Category: Select the required Asset Category from the drop-down menu.

        By default, the All Assets filter is selected.

        Close

      If no filters are selected within the scope, the Next button is disabled.

    • For IaC Alerts, select at least one of the filters below:
        • All Policies: The filter applies to all policies.
        • Severity: Select the required Policy Severity from the drop-down menu.
        • Select Policies: Select to view the Select Existing Policies page, and select the required policies from the table.

          To learn more, see About Security Policies.

        By default, the All Policies filter is selected.

        Close
      • Select one or more template type (Terraform, CloudFormation, Azure Resource Manager, Kubernetes, Helm Charts, Terraform Plan) from the drop-down menu.

        Close
      • Select the IaC scan plugin from the drop-down menu.

        Close
      • Select the IaC repository from the drop-down menu.

        Close

  1. Click Next.
  2. Review the summary of the ignore filter scope.

  1. Click Finish.

All the alerts matching the selected criteria are moved to ignored status.

Related Articles
Adding Alert Ignore FiltersEnabling or Disabling Alert Ignore FiltersEditing or Deleting Alert Ignore Filters