Kaspersky Anti Targeted Attack (KATA) Platform

Removing an IDS rule from exclusions

8 November 2023

ID 247778

You can remove from exclusions a single IDS rule, multiple rules, or all rules at the same time.

To remove an IDS rule from exclusions:

  1. In the program web interface window, select the SettingsExclusions section and go to the IDS exclusions tab.
  2. A list of excluded IDS rules is displayed.
  3. Select the rule that you want to remove from exclusions.

    This opens a window containing information about the rule.

  4. Click Delete.

    This opens the action confirmation window.

  5. Click Yes.

The rule is removed from exclusions. The rule is no longer used for creating alerts.

To remove all or multiple IDS rules from exclusions:

  1. In the program web interface window, select the SettingsExclusions section and go to the IDS exclusions tab.
  2. A list of excluded IDS rules is displayed.
  3. Select check boxes next to rules that you want to remove from exclusions.

    You can select all rules by selecting the check box in the row containing the headers of columns.

  4. In the pane that appears in the lower part of the window, click Delete.

    This opens the action confirmation window.

  5. Click Yes.

The selected rules are removed from exclusions. The rules are no longer used for creating alerts.

Users with the Security auditor role cannot remove IDS rules from exclusions.

Users with the Security officer role do not have access to the IDS exclusion list.

See also

Viewing the table of IDS rules added to exclusions

Adding an IDS rule to exclusions

Editing the description of an IDS rule added to exclusions

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.