Editing the description of an IDS rule added to exclusions

To edit the description of an excluded IDS rule, in the Alerts section:

  1. Select the Alerts section in the window of the program web interface.

    This opens the table of alerts.

  2. Click the link in the Technologies column to open the filter configuration window.
  3. In the drop-down list on the left, select Contains.
  4. In the drop-down list on the right, select the (IDS) Intrusion Detection System technology.
  5. Click Apply.
  6. Click Apt_icon_Importance_new to expand the filter settings list.
  7. Select one or both alert importance levels:
    • Medium—Alert has a medium level of importance.
    • High—Alert has a high level of importance.

    The table displays alerts of medium and/or high importance levels generated by the Intrusion Detection System technology based on IDS rules defined by Kaspersky.

  8. Select an alert for which the Detected column displays the name of the relevant IDS rule.

    This opens a window containing information about the alert.

  9. In the right part of the window, in the Recommendations section, Qualifying subsection, click Edit IDS exception.

    This opens the Edit IDS exception window.

    In the Description field, edit the description of the rule.

    Click Save.

The description of the excluded IDS rule is changed. This rule is no longer used for creating alerts.

See also

Viewing the list of IDS rules added to exclusions

Adding an IDS rule to exclusions

Removing a IDS rule from exclusions

Page top