Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create an exclusion rule

Create a rule to filter or exclude detections from getting converted into vulnerable items (VITs) during ingestion.

Before you begin

Role required: Vulnerability admin

About this task

Procedure

  1. Navigate to All > Vulnerability Response > Exclusion Rules.

  2. On the Exclusion Rule record page, select New to create a rule.

Image omitted: create-exclusion-rule.png
Create exclusion rule
A message saying 'Enable property to automatically close vulnerable items when all associated detections are closed' is displayed. By default, the property is inactive. To enable, select the property link and enter the value as True in the **Value** field.
  1. On the form, fill in the fields.
FieldDescription
NameName of the exclusion rule.
ActiveOption to activate the exclusion rule.
Execution orderUnique order for each exclusion rule.
ConditionFilter conditions for the detections that can be defined while processing them.Note: You can’t select Exclusion rule or Vulnerability item field conditions.
DescriptionDescription of the exclusion rule.
  1. Select Submit.

    The activity is recorded in the system.

    Note: Once an exclusion rule is created, it takes effect on detections starting from the subsequent ingestion.