cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
137
Views
0
Helpful
0
Replies

SNA - Removing false positives

Antonio Macia
Level 7
Level 7

We are getting alarms related to the "UDP Received" security event. After checking the flows, it is Microsoft Teams traffic the one triggering the security event. Is it possible to turno of this security event for traffic using a specific set of ports? I normally create role policies where I turn off alarming for the hostgroup or IPs causing the event, but in this case I want to keep the security event enabled to alarm for other traffic than Teams.

Regards. 

0 Replies 0