Rule tuning - network communication protection

Prev Next

Create a network protection rule search to edit a rule's settings until you get the desired results, without affecting active data analysis.

Option definitions

Category

Option

Definition

Rule options

Name *

Enter a unique name for the search.

Description

Optional field for adding additional information about the search.

Dataset *

Click GUID-6F526415-DCB6-4F53-8296-245AECEC7DE5-low.png to create a data set or select from existing data sets.

Shows the number of appliances and an approximate number of captured events that might be searched as part of this dataset.

The number of captured events is taken from the appliance in the dataset that has the most events to search.

Click Refresh to re-evaluate the number of events that might be searched.

You can edit the dataset if the number is too large, and re-evaluate it until number is acceptable.

Max Results to Report

Select the maximum number of results to display in the Search Results list for each appliance. Default: 100

stop search when max results reached

Select this box to stop the search when the number set in Max Results to Report is reached for each appliance.

When this option is deselected, the search continues and saves all results in the detailed results report.

Results: Store original files as evidence

Creates evidence files from any positive results.

Deselect this option to avoid storage and performance implications.

Condition tab / Exceptions tab

Actions (Exceptions tab only)

Adds or deletes a search exception.

Name * (Exceptions tab only)

Enter a unique name for the exception.

Description (Exceptions tab only)

Optional descriptive text.

State (Exceptions tab only)

Select Enabled or Disabled from the drop-down list. The exception state is independent from the state of the rule that triggered the search.

Classification (Conditions tab only

Select an operator and content classification from the drop-down lists. When required, click GUID-6F526415-DCB6-4F53-8296-245AECEC7DE5-low.png to select a predefined classification.

Network Data Flow

Select the From (or Between) and To network addresses from the drop-down lists.

Protocol Identifier

Click

GUID-6F526415-DCB6-4F53-8296-245AECEC7DE5-low.png

to select a protocol identifier definition.

Save & Run

Select this option to run immediately. The search is added to the list of searches.

Save

Select this option to save and run later. The search is added to the list of searches.

Cancel

Cancels the search without saving.



* indicates a required field