Add in detections a pre-filter that selects all rules that are not ok #13284
-
Can you in SO 2.4 make a detection dashboard pre-filter that filter out all the rules that have sync issues? if you go to the hunt dashboard you find the "intCheckId" but this is not the rule ID, how do you find the ruleid of rules with a sync issue regards Bart |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 6 replies
-
The Integrity Check Report log will look something like this (if the integrity check failed):
The ids in |
Beta Was this translation helpful? Give feedback.
-
Hello Josh, I have found 25 rules in this field over a period of 60 days and none of these rules have tweaks, when i disabled these rules status wass still " Rule Mismatch" I do not have local rules this was the filter that i used for filtering rules
This was the filter that I used for the sec logs
|
Beta Was this translation helpful? Give feedback.
Ok, you need to remove
- re:DNS Query
from/opt/so/saltstack/local/pillar/idstools/soc_idstools.sls
, runsudo salt-call state.apply idstools
and then sync suricata in Detections. Give it an hour or so and then lets go from there.