FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
Andy_G
Staff
Staff
Article Id 191795

Description

Summary of Topic

In order for an exception condition for a rule to work as desired all attributes used in an exception must be referenced in both the Group By section of the Rule sub pattern and the Incident Attributes.

If either of these requirements are not met then the rule exception will not work.

 

Example:

I have taken our system rule,  Multiple Admin Login Failures: Net Device, and added an exception to not fire the rule if the User attribute is Santa.

 

Here is the subpattern, which is not modified:

agodwin_FD39628_tn_FD39628-1.jpg

Here is the incident definition, which is also not modified:

agodwin_FD39628_tn_FD39628-2.jpg

Here is the exception:

agodwin_FD39628_tn_FD39628-3.jpg

Notice all 3 contain the attribute User.

 

Additional Resources

n/a

 

Version Application

All

 

 

Contributors