cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Content Packs and disabling rules

When installing or updating content packs some of the accompanying notes recommend disabling some rules to avoid duplicate events. Is there a way to do this other than one by one in the policy editor?

Thanks

14 Replies
Former Member
Not applicable
Report Inappropriate Content
Message 2 of 15

Re: Content Packs and disabling rules

You can control-click multiple events and click the Action Title Bar to change them all, but I'm not sure if that's what you had in mind.

Re: Content Packs and disabling rules

Hi Andy

No, not quite. What I want to do is find a way to select the rules that need disabling. A the moment I can enter a single Sig ID like this:

25-11-2015 12-44-01 PM.png

If I try to use contains(47-4000057,47-4000058), for example, I see this

25-11-2015 12-48-14 PM.png

In fact, anything other that a single Sig ID returns that ER1193. If I can't select multiple Sig IDs from within the console is there an NSQL UPDATE query I could run from an ssh session?

Former Member
Not applicable
Report Inappropriate Content
Message 4 of 15

Re: Content Packs and disabling rules

Mark,

Thank you for the context. Fortunately, in this instance, we can use multi-click to make it a bit easier. I did verify the Sig ID's. Just highlight Correlation Engine | Recon* and set to disable. I'll suggest the Recon content pack description to be simplified. Thanks.

Capture2.PNG

Former Member
Not applicable
Report Inappropriate Content
Message 5 of 15

Re: Content Packs and disabling rules

The Content Pack documentation allows for you to copy and paste the signature list directly and place it in the Signature ID filter.  The Signature ID filter allows for a comma separated list.  For instance the current version of the Recon Content Pack lists a number of Signature IDs.  Copy the list and paste it into the Signature filter, hit refresh and it will display all of them.  You can then use Ctrl-Click or Shift-Click to select multiples from the list to disable them.

SigFilter.png

Former Member
Not applicable
Report Inappropriate Content
Message 6 of 15

Re: Content Packs and disabling rules

This is the right answer, albeit it should be made more obvious...

Re: Content Packs and disabling rules

This only works if the spaces after the commas are removed. probably the only option I had not tried.

Thanks to Andy and muser for clearing this up for me.

Re: Content Packs and disabling rules

Just going through the content packs on my ESM and the Recon pack has the Sig IDs (all 50-odd of them) comma separated without spaces...

Copy/paste has saved me heaps of time.

One last question: is it possible to do a wild card search on the Sig ID field?

Former Member
Not applicable
Report Inappropriate Content
Message 9 of 15

Re: Content Packs and disabling rules

Exactly. And I learned that is intentional for that reason.

Wildcards are supported when searching using 'contains' from the Global Filter in the view, but that little trick doesn't work in the Sig ID field in the Policy Editor.

Re: Content Packs and disabling rules

So, who do we prod with a stick to make sure the Content Pack notes are consistent, ie all rules to be disabled or aggregation turned off have the spaces removed for a straight copy/paste? I'm guessing there's disparate teams producing these packs...?

I've noticed filters that work in the Global Filter view that don't work elsewhere in a different context - I'll save that for another thread.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community