Examples: Filter alerts
This topic lists some basic examples for filtering alerts.
Asset Manager
This example assumes that you are looking for users trying to access blacklisted applications and processes (shadow IT). The filter results can help you decide whether to delete the Blacklist rule and reduce alerts or Enforce the rule and continue receiving alerts.
Policy Manager
This example assumes that you are looking for applications and processes with the Unknown trust value and set an appropriate Trust value using the MD5 Override feature.