All Apps and Add-ons

get correct "Block Rules"

jaxjohnny2000
Builder

According to the details section of the instruction for this app: "to get correct "Block Rules" statistics you have to create a last ruleset with a rule named "Last Rule" which is active in all cycles (Request, Response, Embedded)."

How is this done?

I reviewed that documentation, but there are no details about that rule set. It simply says create a rule set and make it active with no details about what the rule set is supposed to contain. Is there a way to get clarification on what is expected there?

PavelP
Motivator

Hi

You have to create a ruleset named "Last Ruleset" in the bottom of your ruleset tree, then create a rule named "Last Rule" inside it. That's all!

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...