I'm seeing a lot of alerts for http-probing scenario for a specific endpoint that is behaving as expected (eg, this isn't malicious traffic). I could disable this scenario, but I wonder if there's any other way to handle this, like allowlisting based on URL or something else.