All EDR's are noisy tools, and we at SonicSentry rely on that noise and data to accurately detect and respond to activities within your environment. We have dedicated experts disseminating what's benign, what's expected behavior for routine updates, and what activities need additional attention paid to them.
Saying that, YOU know your environment, what's permitted, and what's not. You can play a role in keeping a clean and relevant baseline in your environment, as well as singling out unapproved use of controlled tools by playing an active role in Alert Management within your environment.
The default view of the Alerts page is set to show ONLY 'High' and 'Severe' logs that the agent categorizes as 'Alerts' covering the last 30 days.

By clicking on the columns button to the right of the filters search bar, you may customize the information displayed on the alert screen.

When selecting an alert, you are given multiple Actions to choose from within the alert.

To use this Action, you must have an active Respond Policy in your portal. This will create a Custom Response for the event and will occur each time it is detected by any agent with the policy applied.

Acknowledging an alert simply tells the portal "I have seen this" removes it from your New Alert count, and removes it from your Alert View list. To see these alerts again, simply select 'Show Acknowledged Alerts'.
Creating a suppression rule will acknowledge the alert, and any future events. The matching events will still be logged, but only visible when selecting 'Suppressed' from the Severity filter
A general guideline to Rule and Alert suppressions is to utilize as much granularity as possible.
