Muting
Muting allows you to ignore authorized and expected behaviors to identify anomalies for the specific host. When a detector is muted, any related detection will have a status of Muted. This means a notification will not be generated for the detection. A muted detection will auto-resolve after the specified time frame or can be resolved manually.
To view all muted devices, detectors, and detections, go to the Mutes and Excludes.
Mute all detectors for a device
Muting a device for all detectors is most commonly used for devices such as sandboxes and vulnerability scanners, which routinely trigger detections as part of their normal operation. Because these alerts are expected, muting such devices is often one of the first steps when configuring FortiNDR Cloud.
To mute a device for all detectors:
- Go to Detections > Triage Detections.
- In the toolbar, click the gear icon
and select Muted Devices. The Mutes and Excludes page opens. - Scroll down to the Muted Devices section and click Add New device Range.
- Configure the muted device/range.
Setting
Description
Device IP or Range Enter an IP address or CIDR range. Detector Select a detector from the dropdown. Description Add an optional description of the device(s). - In the Device IP or Range field, .
- Click Add Device(s).
Mute a detector
Muting a detector will cause all its future detections to be muted, regardless of which device triggered the detector. This is commonly used for posture-aware detectors that identify approved or expected behavior.
To mute a detector:
- Go to Detections > Triage Detections.
- In the toolbar, enable table view
. - In the Actions column, select Mute Detector.

- In the dialog that opens, enter a comment in the Comments field, and click Mute Detector.
Mute a device
You can mute a device for a detection, detector or an account. This is commonly used for suspicious behaviors from approved devices, such as remote access from an administrator workstation. Detections that contain a muted detector are appended with Muted in the Status of column of the Detections Table.
To mute a device from Triage Detections:
- Go to Detections > Triage Detections and open a detector.
- In the Impacted Devices tab, select the detection that contains the device and detector.
- In the Actions column, click the actions menu and select one of the following options:
- Mute Device for Detection
- Mute Device for Detector
- Mute Device for Account
- In the dialog that opens, enter a comment in the Comments field, and click Mute Device.
To mute a device from the Detections Table:
- Go to Detections > Detections Table.
- Select a detection in the list.
- In the Actions column, click the actions menu and select one of the following options:
- Mute Device for Detection
- Mute Device for Detector
- Mute Device for Account
- In the dialog that opens, enter a comment in the Comments field, and click Mute Device.
Viewing muted devices
|
From |
Description |
|---|---|
|
Mutes and Excludes |
|
| Detections |
|
| Detections Table |
|
and show the Device Muted column.