Handling false positives
Another way of handling false positives is to add any IP addresses used by your organization (that might appear in the BMC Defender list, but are necessary or known to your organization) to the @@block_exceptions@@ macro on the Correlation > Config > Lists screen. This macro typically contains a list of IP addresses that are not blocked under any circumstances. (The user simply updates the list of IP addresses like any other list macro.) The correlation rules in the Correlation > Threads screen references a rule @ip_blocklist@@ and not @@block_exceptions@@, that indicates that a match has to occur in the @@ip_blocklist@@ macro, and not occur in the @@block_exceptions@@ list.
Finally, if you have chronic problems with certain ranges of devices, you should contact BMC Support to review your situation. The BMC Defender reputation database is easily modified to exclude certain IP addresses that might be necessary for your site.