Forum Discussion

Rob Kennedy's avatar
Rob Kennedy
Copper Contributor
Aug 23, 2017

User + Server exclusions

Following a recent deployment of Advanced Threat Analytics (ATA) my client is getting "Remote execution attempt detected" alerts for their Veeam backup service account against several servers. This is a known service account and they would like to exclude the alert for this activity for just this user account. However ATA only provides an option to exclude the server. 

 

Do we know if providing the ability to exclude both a specfic user and server is on the ATA roadmap?

  • firatkutay's avatar
    firatkutay
    Copper Contributor

    Currently, Advanced Threat Analytics (ATA) allows exclusions based on either users or servers, but not both simultaneously. There isn't explicit confirmation about this feature being on the roadmap or i couldn't find.

Resources