You can ignore observables on EclecticIQ Intelligence Center to prevent observables with a given type and value from being ingested.
Do this to reduce false-positives and noise in your datasets.
Ignore with observable rule#
Delete and ignore#
Delete and ignore an observable to:
remove that observable from EclecticIQ Intelligence Center, and
prevent EclecticIQ Intelligence Center from subsequently ingesting or extracting new observables with the same type and value.
Delete and ignore performs a “soft delete” on an observable. This:
Prevents from being displayed on EclecticIQ Intelligence Center,
but leaves records in PostgreSQL and Elasticsearch.
You can filter records to look for ones with the field
See About search for more information.
To do this:
Locate the observable you want to remove.
From entity builder