cancel
Showing results for 
Search instead for 
Did you mean: 

Delete Max datasource rule count exceeded

Hello everyone.

I've read the other posts and followed all the recommendation but wanted to know if there is a way to determine which table was the affected. I don't want to delete everything because there is a possibility that some events would not be learned again and remain as 0.

These messages keep appearing on Windows devices but as far as I know you cannot turn on Parse as generic syslog on those, Right?

The KB77341 says I can only have 25,000 per category but what are the categories? Is a datasource a category?

If someone knows how to delete only the affected or would it be better to delete all auto learned rules?

 

Thanks

Labels (1)
More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community