foxsec-pipeline icon indicating copy to clipboard operation
foxsec-pipeline copied to clipboard

Filter out amo_cloud_submissions alerts from PostProcessing's alert summary analysis

Open ajvb opened this issue 5 years ago • 2 comments
trafficstars

Add support for filtering out certain alerts within the alert summary analysis in post processing. Then, filter out amo_cloud_submission alerts specifically.

ajvb avatar Apr 10 '20 20:04 ajvb

@ajvb I'm wondering if we should rephrase this issue and instead of whitelisting certain users, just add the ability to filter certain alerts in post processing analysis?

In this case these alerts aren't really indicative of an issue and are more informational, so I'm not sure if it makes sense to take them into account in the anomaly detection.

ameihm0912 avatar Apr 13 '20 18:04 ameihm0912

@ameihm0912 That sounds good to me. Changing.

ajvb avatar Apr 14 '20 17:04 ajvb