- 07 Aug 2023
- 1 Minute to read
- Print
- DarkLight
- PDF
Managing Findings Rules
- Updated on 07 Aug 2023
- 1 Minute to read
- Print
- DarkLight
- PDF
Editing a Findings Rule
You can edit the configuration of a findings rule.
Note that when you modify a rule, the Alert History changes its pointers to the alerts accordingly, but the data becomes inaccessible.
For example, let's say you create a device-query rule and it runs for some time and creates alerts. When you modify that same rule to be user-query based, the old links that are used to pivot to assets from the Alert drawer no longer work.
To edit the rule configuration
- In the Rules Manager table, click a rule.
Its Rule drawer opens. - In the Rule drawer Rule Configuration tab, update parameters or settings (refer to creating a new rule), as required. The Save Changes button becomes enabled.
- Modify the external notification, if required.
- Click Save Changes.
Modifying the External Notification
You can choose an alternate enforcement action for a different external notification or modify the configuration of the existing one.
To modify the external notification
- Click the
Edit icon.
- Modify the configuration of the external notification, by doing one of the following:
- In Select Action, choose another enforcement action and fill in the required fields.
- Modify the configuration of the current enforcement action.
- Click Apply.
Activating/Deactivating a Findings Rule
A rule runs only while it is activated.
To activate a rule
- In the Rules table, click a rule, and in the Rule drawer that opens, toggle on Activate (default).
- Click Save Changes.
To deactivate a rule
- In the Rules table, click a rule, and in the Rule drawer that opens, toggle off Activate.
- Click Save Changes.
Deleting Findings Rules
You can delete one or more findings rules.
To delete one or more rules
- In the Rules Manager table, select the checkboxes of one or more rules, and then from the Actions menu, click Delete.
- In the confirmation message, click Delete. The selected rules are removed.