Automatically activate rules from certain categories and severities #14058
-
Hi, |
Beta Was this translation helpful? Give feedback.
Replies: 5 comments 3 replies
-
Have you considered regex? |
Beta Was this translation helpful? Give feedback.
-
Hi, So if I disable a rule in detections manually because it triggers too many false positives it then gets activated again later on automatically if it matches the regex. Amy advice on how to do this? |
Beta Was this translation helpful? Give feedback.
-
Have you considered suppressing the individual rule? That way it can be enabled but won't actually generate alerts: |
Beta Was this translation helpful? Give feedback.
-
Hi Doug, |
Beta Was this translation helpful? Give feedback.
-
Hi Dough, |
Beta Was this translation helpful? Give feedback.
Deactivating a rule does save a very small amount of RAM and CPU. For a small number of rules, you probably won't notice a difference between deactivating and suppressing. The point at which you would notice depends on several variables like the specs of your system and how much traffic you're monitoring.