<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNA - Removing false positives in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/sna-removing-false-positives/m-p/5571364#M1307</link>
    <description>&lt;P&gt;You could add the MS Teams Public IPs to a trusted outside hosts group for which you disable this alarm. Did you try that already?&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2026 14:02:27 GMT</pubDate>
    <dc:creator>rschlayer</dc:creator>
    <dc:date>2026-08-26T14:02:27Z</dc:date>
    <item>
      <title>SNA - Removing false positives</title>
      <link>https://community.cisco.com/t5/security-analytics/sna-removing-false-positives/m-p/5547578#M1281</link>
      <description>&lt;P&gt;We are getting alarms related to the "UDP Received" security event. After checking the flows, it is Microsoft Teams traffic the one triggering the security event. Is it possible to turno of this security event for traffic using a specific set of ports? I normally create role policies where I turn off alarming for the hostgroup or IPs causing the event, but in this case I want to keep the security event enabled to alarm for other traffic than Teams.&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 07:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/sna-removing-false-positives/m-p/5547578#M1281</guid>
      <dc:creator>Antonio Macia</dc:creator>
      <dc:date>2026-04-23T07:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: SNA - Removing false positives</title>
      <link>https://community.cisco.com/t5/security-analytics/sna-removing-false-positives/m-p/5571364#M1307</link>
      <description>&lt;P&gt;You could add the MS Teams Public IPs to a trusted outside hosts group for which you disable this alarm. Did you try that already?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 14:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/sna-removing-false-positives/m-p/5571364#M1307</guid>
      <dc:creator>rschlayer</dc:creator>
      <dc:date>2026-08-26T14:02:27Z</dc:date>
    </item>
  </channel>
</rss>

