2013-06-21
05:22 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Need help for exception on correlation rules
Hi
I have some correlation rule which alert me when software is installed, rule base on on some windows MsiInstaller eventID 1022.
Now i tried to make some exceptions for kind of software like Windows patches, Antivirtus patches, and so one. I realized that i have to use minimum 4 variables contrition:
Event Description
Object Name
Object Type
Product,
Sometimes some variable are present in this variable sometimes are not.
My exceptions are in attachment
Unfortunately i get still alerts when for example Object Type is equal 'Update Patch'.
- Tags:
- Community Thread
- correlation
- Discussion
- enVision
- exception
- for
- Forum Thread
- help
- need
- on
- RSA enVision
- Rules
0 Replies
