Software Secure Workload
Activity Configure

Policy Discovery Flow Filters

If certain flows are generating unwanted policies, you can exclude those flows from automatic policy discovery using exclusion filters. For example, certain protocols like ICMP in the final allow list model, you can create an exclusion filter with a protocol field set to ICMP.


 
  • Conversations that match exclusion filters are excluded for the purposes of policy generation and clustering, but remain in the Conversations View with red ‘excluded’ icon (see the Table View in Conversations). Also, workloads of the workspace incident on such conversations remain viewable as well.

  • An exclusion filter that uses a cluster or a filter definition from a workspace is effective only in primary workspaces, else, its cluster definitions are not visible to the label system, and any matching conversations are not excluded.

  • Exclusion filters are versioned and to track modifications, see Activity Logs and Version History.

  • For limits on the number of exclusion filters, see Limits Related to Policies.

You can create one or both of the following, then enable either or both when discovering policies:

  • A list of exclusion filters for each workspace.

  • A list of default exclusion filters that is available to all workspaces in your tenant.

You can also enable or disable either or both lists for the Default Policy Discovery Config.

For instructions, see: