Exclude patterns from learned patterns
Exclude CI-based or CI class-based alerts and patterns when you encounter alerts incorrectly added to a learned pattern by the Learned Patterns job. For example, a pattern might include an alert that occurred at the same time as other alerts but is not actually related to them. This maintains accuracy, ensuring better alert groupings and improved management efficiency.
Before you begin
Role required: evt_mgmt_admin
About this task
You select the incorrect alert in a pattern to exclude the entire pattern to which it belongs.
Note: When you exclude an incorrect alert, any other patterns containing that alert are also excluded.
Procedure
- Navigate to All > Event Management > Reporting > Learned Patterns.
Exclude pattern navigation
- On the Learned Patterns page, expand the anomalous pattern.
Expanded patterns
Select the pattern name to open it for exclusion.
On the SA Alert Aggregation Learned Pattern page, select Exclude.
Option to exclude the selected pattern
Result
The entire pattern is removed from the Learned Patterns report and listed on the Excluded Patterns page, located at Event Management > Administration > Excluded patterns.
If the pattern includes other alerts, you can restore it by reclaiming those alerts as a learned pattern. For further details, see Restore excluded patterns.