auto ignore Salt connection Alerts #2648
Replies: 1 comment 2 replies
-
You can filter these out from the Wazuh alerts by modifying the Wazuh rules. However, we may need to consider making a default filter/modified rule for these. |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
I'm seeing a lot of 'sudo root' alerts that look like they're nothing more than the automated Salt checkins by from the Sensors to the Manager. Shouldn't that particular Alert be ignored with an auto-created BFP rule during setup since it's a known connection setup by the Admin?

Beta Was this translation helpful? Give feedback.
All reactions