Jump to content

Some exclusions resolve detections unreliably


tacotuesday

Recommended Posts

I'm having an issue with several exclusions.  Exclusions that previously worked are failing to resolve some new detections.  If I open the exclusion, and then click the "Update Exclusion" button without changing anything, the detection(s) will then be resolved.  Has anyone else experienced this?
 

Attached is an example detection and exclusion.  After I took a screen shot of the exclusion criteria, I clicked the "Update Exclusion" button.  When I went back to the detections screen the detection had been removed.

 

Inspect 2.png

 

Inspect 1.png

Edited by tacotuesday
Link to comment
Share on other sites

  • Administrators

Please try changing from upper case (Operations -> operations and Condition -> condition). Albeit it should not matter, we'd need to be sure this is not the issue.

If it doesn't make any difference, enable diagnostic information / logging for the particular detection. After the detection has been triggered, you should see here a link to diagnostic files. Please raise a support ticket and provide this link along with the issue details to technical support.

image.png

Link to comment
Share on other sites

Thank you for the reply Marcos.

I'll try to remove the signature type and change the case on "Operations" and "Condition".

I don't have a diagnostician information option for my detection.  Do I need to enable it somewhere?

 

Inspect 3.png

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...