azure-docs icon indicating copy to clipboard operation
azure-docs copied to clipboard

Anomaly scoring - No Severity available for understanding thresholds for Blocked Requests (score over 5)

Open moneyclouds opened this issue 10 months ago • 2 comments

I have a use case with a customer where they are seeing Blocked Requests, but there isn't any info/data/metrics available for querying to understand what each TransactionID/RuleID is mapped to what severity or category level. ***

Would it be possible for the Severity to be added for the Managed Rules Sets? That way we can understand how to mitigate against false negatives or false positives when trying to build a security structure.

CRS gives this site as a guideline reference, but we do not show this in our docs: https://www.netnea.com/cms/core-rule-set-inventory/

Any guidance or help is appreciated. Thank you!


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

moneyclouds avatar Apr 23 '24 21:04 moneyclouds

@moneyclouds Thanks for your feedback! We will investigate and update as appropriate.

TPavanBalaji avatar Apr 24 '24 04:04 TPavanBalaji

@moneyclouds I'm going to assign this to the document author so they can take a look at it accordingly.

@vhorne Can you please check and add your comments on this doc update request as applicable.

SaibabaBalapur-MSFT avatar Apr 27 '24 18:04 SaibabaBalapur-MSFT

Thanks for your dedication to our documentation. We have created an internal work item in our backlog to resolve this issue. If you determine another possible update to our documentation, please don't hesitate to reach out again.

#please-close

vhorne avatar Jul 01 '24 15:07 vhorne