The Detection and Response policy type's Endpoint Activity Recorder rules in your environment will not prevent incidents from being created for 8xxx events. It has no impact on incident creation only on event collection. The product and policy are working as designed.
How can I prevent my application from generating an incident?
- Incident Rules can be disabled if a specific rule is generating false positives in your environment and no malicious incidents are being created for that rule.
- See the SES documentation About incident rules or Incident Rules
- Creating exceptions in the relevant SESC policies may shape better what is collected and submitted to the cloud console. This may include one or more of the following and may not be limited to the following policies:
- App Control
- Detection and Response
- IPS
- Whitelist
- Submit non-emergency false positives using the Incorrectly Detected by Symantec tab at https://symsubmit.symantec.com/
You do not have to open a support case for non-emergency requests.
- Apply latest definitions to the SES agent.
- It is also recommended that you review the SES documentation on
Using Adaptive Protection in the online technical documentation.
PLEASE NOTE that it is outside the scope of support to manage or create policy changes in a customer environment. What policy changes may be required in your environment will differ from other customer environments.