cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Create a filter for an application with multiple signatures?

Jump to solution

Hello,

I'm wondering if there is an easy way to filter out events where the "Application" field is the same, but where different Signature IDs are involved. 

We have some VmWare ESX servers which are VERY chatty.  All of the events coming in with the application "vxpa" are not useful from a security perspective.  I could disable the ASP rules one by one, but there are a lot of them involved. 

Any help is apperciated!

Thanks,

- Steve

1 Solution

Accepted Solutions
akerr
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 5

Re: Create a filter for an application with multiple signatures?

Jump to solution

Content strings are just a very simple string match, rather than regex.  So it should work, but I'd be hesitant to base it on such a short string.

View solution in original post

4 Replies
akerr
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 5

Re: Create a filter for an application with multiple signatures?

Jump to solution

You absolutely can write filters, but they happen before the parsers, so you'll have to do it with regex.  

In the Policy Editor, Expand Receivers and click Filters.  You can add a new filter there.  I'd suggest only enabling it on the data sources you want it to apply to however, rather than globally.

Re: Create a filter for an application with multiple signatures?

Jump to solution

Hi akerr,

Thanks for the response.  I do know about the filters, and have written a bunch.  However, for each of these different signatures that are involved, I'd need to write a different Regex, which will be a lot of work.  That's why I was looking for an easier solution. 

The other part of the filter rules (besides PCRE) is "Content Strings."  I thought that if I put "vpxa" as a content string and made it case-insensitive, that would do the trick.  Certainly "vpxa" is a string that is in these packets.  However, it doesn't seem to work.  Is there a particular format for content strings?

Thanks,

- Steve

akerr
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 5

Re: Create a filter for an application with multiple signatures?

Jump to solution

Content strings are just a very simple string match, rather than regex.  So it should work, but I'd be hesitant to base it on such a short string.

Re: Create a filter for an application with multiple signatures?

Jump to solution
Thank you! I created the filter and it seems to be working (I'm not sure what I did wrong with the content string the first time.) I'll play with it and make sure that it's not "too" effective.
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community