Video Screencast Help
Search Video Help Close Back
to help
New in the Rewards Catalog: Vouchers for "Symantec Technical Specialist" and "Symantec Certified Specialist" exams.

Enabling rule changes

Updated: 21 May 2010 | 2 comments
Steelejaxon's picture
0 0 Votes
Login to vote

New to SSIM. I have made several changes to the correlation rules (ex. changed the Windows account lockout to excude a certain username who frequently gets locked out). However, even after making the change, I am still getting incidents based on these changes. Another examples is the Spyware Not Quarentined events. I made a change to exclude any events in which the words "google search bar" appear in the Name field as this is a common false positive for us. Again, I have seen incidents with events which should be excluded pop up after I made the changes. I have the custom (User) rule checked and the default (System) is deselected. Any ideas?

Comments

Laurent_c's picture
07
Nov
2009
0 Votes 0
Login to vote

this might be a known issue

this might be a known issue already resolved in MP2. What level of patch is your ssim appliance ?

Steelejaxon's picture
09
Nov
2009
0 Votes 0
Login to vote

looks like 4.6.2.21

looks like 4.6.2.21