When installing or updating content packs some of the accompanying notes recommend disabling some rules to avoid duplicate events. Is there a way to do this other than one by one in the policy editor?
Thanks
You can control-click multiple events and click the Action Title Bar to change them all, but I'm not sure if that's what you had in mind.
Hi Andy
No, not quite. What I want to do is find a way to select the rules that need disabling. A the moment I can enter a single Sig ID like this:
If I try to use contains(47-4000057,47-4000058), for example, I see this
In fact, anything other that a single Sig ID returns that ER1193. If I can't select multiple Sig IDs from within the console is there an NSQL UPDATE query I could run from an ssh session?
Mark,
Thank you for the context. Fortunately, in this instance, we can use multi-click to make it a bit easier. I did verify the Sig ID's. Just highlight Correlation Engine | Recon* and set to disable. I'll suggest the Recon content pack description to be simplified. Thanks.
The Content Pack documentation allows for you to copy and paste the signature list directly and place it in the Signature ID filter. The Signature ID filter allows for a comma separated list. For instance the current version of the Recon Content Pack lists a number of Signature IDs. Copy the list and paste it into the Signature filter, hit refresh and it will display all of them. You can then use Ctrl-Click or Shift-Click to select multiples from the list to disable them.
This is the right answer, albeit it should be made more obvious...
This only works if the spaces after the commas are removed. probably the only option I had not tried.
Thanks to Andy and muser for clearing this up for me.
Just going through the content packs on my ESM and the Recon pack has the Sig IDs (all 50-odd of them) comma separated without spaces...
Copy/paste has saved me heaps of time.
One last question: is it possible to do a wild card search on the Sig ID field?
Exactly. And I learned that is intentional for that reason.
Wildcards are supported when searching using 'contains' from the Global Filter in the view, but that little trick doesn't work in the Sig ID field in the Policy Editor.
So, who do we prod with a stick to make sure the Content Pack notes are consistent, ie all rules to be disabled or aggregation turned off have the spaces removed for a straight copy/paste? I'm guessing there's disparate teams producing these packs...?
I've noticed filters that work in the Global Filter view that don't work elsewhere in a different context - I'll save that for another thread.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA