The process of classifying IDPS alerts so that they can be more effectively managed. An IDPS administrator can set up alarm filtering by running the system for a while to track the types of false positives it generates and then adjusting the alarm classifications. for example the administrator may set the IDPS to discard the alarm produced by false attack stimuli or normal network operations. Alarm filters are similar to packet filters in hat they can filter items by their source or destination IP addresses, but they can also filter by operating systems, confidence values, alarm type, or alarm severity.