FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
FortiKoala
Staff
Staff
Article Id 195219
Description

How to include or exclude specific machines from a custom rule


Scope

FAQ


Solution

By default rules in ZoneFox apply to all machines which have agents sending events to the Collector Server.  However custom rules can also be set to apply to only a specific set of machines, or to all but a specific set of machines.


Note that ZoneFox only knows about machines that already have agents installed and sending events, so rules may have to be modified after their initial creation, and after new agents are installed.


ZoneFox converts machine names to their unique internal agent ID, this is is displayed when you edit a rule already containing some machine names.


To add machine names to an existing rule:


  1. Navigate to the RULES page
  2. Click on the rule name to open the Rule Wizard
  3. Click on the Next button
  4. In the Summary view, scroll down to the Machines section and click on the edit option:

  5. Toggle on the Filter by Machine option, then click on the SEARCH MACHINES button

  6. In the Machine Lookup window, either leave the textbox blank and click on the SEARCH button to see all the machine names available, or enter part of a machine name to filter on that value:

  7. Select the required machine names and click on ADD

  8. Note that the agent ID is now displayed instead of the machine name:

  9. Select either Monitor these Machines or Monitor all BUT these Machines, then click on DONE

  10. SAVE the changes to your rule



Contributors