Only Kaspersky Lab IOA rules can be added to the white list. If you do not want to apply a user-defined IOA rule for scanning the events database, you can disable that rule or delete it.
To add an IOA rule to the white list from the Alerts section:
The table of alerts opens.
The table displays alerts generated by IOA rules.
This opens a window containing information about the alert.
This opens a window containing information about the rule.
The IOA rule is added to the white list. This rule will be skipped during events database scans.
To add an IOA rule to the white list from the Threat Hunting section:
The event search form opens.
You will see a list of servers on which events meeting the defined criteria were detected.
This opens a window containing information about the event.
This opens a window containing information about the alert.
This opens a window containing information about the rule.
The IOA rule is added to the white list. This rule will be skipped during events database scans.