cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Former Member
Not applicable
Report Inappropriate Content
Message 11 of 15

Re: Content Packs and disabling rules

Actually there is a single PM responsible for content packs and he's meticulous and always looking for feedback. Please forward or post suggestions and you'll see a quick response.

I think the difference is that the Global Filter (as it is when used for views) includes the regex functionality, but the Policy Editor doesn't. It would be a nice to have for the Policy Editor but I think we'll see a new UI first.

Re: Content Packs and disabling rules

I'd be happy to liaise with the PM directly but in lieu of that, the points highlighted in thread would be a good start ie consistency within the various content packs for listing rules to be disabled. I think that the application of Content Packs should be simplified whether it be for McAfee PS, Consultants/Partners or the end user.

I'm sure we will see a new UI first... HTML5 etc, etc. All well and good but it doesn't seem likely to address one on my clients' biggest bug bears. No right click functionality. But I digress. The filter issue, in this case, is between Global Filters and alarms & correlation rules. It does beg the question why some functionality is available in some places and not others. Ever the spotted the inconsistency in whether a modal window can be maximised or not?

Former Member
Not applicable
Report Inappropriate Content
Message 13 of 15

Re: Content Packs and disabling rules

I'll highlight this thread for him. The only place I see the sig ID's listed is in the Content Pack description and they don't have spaces. Is there another place they are listed?

As for the UI, I'll say with first hand knowledge that there is most definitely a right-click. I appreciate the flash UI for what it is but it helps sometimes to know the back stories of how some of the features came to be. There's usually a reason something is the way it is, but not always

Re: Content Packs and disabling rules

Look at the the DNS and DoS packs. The content description lists the Sig IDs to be disabled but they are comma delimited WITH spaces. Then look at the Recon pack. That one shows the Sig IDs comma delimited with no spaces. Consistency...

So, you're saying that the next release has a usable right click function? By usable, I mean something like showing the equivalent of Event Summary|Event Drilldown|Events at the very least.

Former Member
Not applicable
Report Inappropriate Content
Message 15 of 15

Re: Content Packs and disabling rules

Thanks for pointing them out. I'll see what I can do.

And yes, 10.0 will include useful right-click functionality.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community