- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
InfoSec - Continuous Monitoring - Intrusion Detection Dashboard
AJSCSA
Loves-to-Learn Lots
07-28-2021
12:10 PM
Would someone be able to help me understand how do to this? I would like to modify the built in dashboard in the InfoSec APP to exclude a specific source IP address. The default search the dashboard uses is below.
| tstats summariesonly=true allow_old_summaries=true count from datamodel=Intrusion_Detection.IDS_Attacks where * IDS_Attacks.severity="*" by IDS_Attacks.signature, IDS_Attacks.severity | rename "IDS_Attacks.*" as "*" | sort severity
Currently, that dashboard visual is full of events from my vulnerability scanner running scans.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
rcruz
New Member
07-20-2023
06:41 AM
| tstats summariesonly=true allow_old_summaries=true count from datamodel=Intrusion_Detection.IDS_Attacks where * IDS_Attacks.severity="*" IDS_Attacks.severity="IP TO BE EXCLUDED" by IDS_Attacks.signature, IDS_Attacks.severity | rename "IDS_Attacks.*" as "*" | sort severity
Replace the IP TO BE EXCLUDED with the actual IP.
