Yes. Along with complete turn ON/OFF, rules have facility to add whitelists. The rule whitelists are collection of criteria. The events matching any of the criteria in this collection get skipped during rule evaluation. To add whitelist criteria to any rule, click on the rule ‘Title’ to go to the ‘Rule Information’ page. This page has a ‘Manage Rule Whitelists’ section to create, edit and remove the whitelists. To create new whitelist, select an attribute name from the ‘Fields…’ dropdown and add value against it in the text box. For example, to skip a machine having IP 10.10.10.55 from rule r1 evaluation, add field as ‘ip-initiator’ and set value as ‘10.10.10.55’. This will prevent all network events initiated by 10.10.10.55 from getting evaluated by that rule. Multiple values can be added against an attribute name in the same test box (each value on new line). Multiple such fields can be added to same criteria with ‘+ Add Field’ button.