Kaspersky Next XDR Expert

Adding exclusions from the Adaptive Anomaly Control rules

The Add to Adaptive Anomaly Control exclusions wizard allows you to add exclusions from the Adaptive Anomaly Control rules for Kaspersky Endpoint Security.

To add exclusions from the Adaptive Anomaly Control rules by using the wizard:

  1. Start the wizard in one of the following ways:
    • In the main menu, go to OperationsRepositoriesRule triggers in Smart Training state, select one or several detections, and then click the Exclude button.

      You can add up to 1000 exclusions at a time.

      Before adding a detection to exclusions, you can view the properties of the detection by clicking the detection name or the Properties button. In the detection properties window that opens, you can also click the Exclude button.

    • In the main menu, go to Monitoring & reportingEvent selections, click the link with the event selection you need, select the check box next to the detection you want to exclude, and then click the Exclude from Adaptive Anomaly Control button.

    The Add to Adaptive Anomaly Control exclusions wizard starts. Proceed through the wizard by using the Next button.

  2. Select the policies and profiles to which you want to add exclusions.

    Inherited policies cannot be updated. If you do not have the rights to modify a policy, the policy will not be updated.

  3. Click Done to close the wizard.

The status of the detection is changed to Excluding. The detection disappears from the list of detections after the next synchronization of the client device with the Administration Server. The exclusion from the Adaptive Anomaly Control rules is configured and applied.