- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-05-2023 02:02 AM
Hello everyone,
I need your help because I want to create a BIOC deletion rule, I have the hash, the username and the path but I would like this deletion to be effective during a specific time slot, can it be configured?
01-05-2023 10:08 PM
Hi @S-LEGOUGE ,
Avoiding a BIOC rule to get a hit and generate an alert can happen in 3 ways only:
Correlation rule is another mechanism of creating alerting rules as per your choice on the basis of XQL queries and scheduling the XQL to run for a time frame in a particular period.
Hope this helps!
Please mark the answer "Accepted as Solution" if it does
Regards
01-05-2023 07:07 AM
Hi @S-LEGOUGE ,
Thank you for writing to live community!
IOC/BIOC suppression rule cannot be schduled as they are global by nature and real time.
01-05-2023 08:29 AM
Hi @neelrohit
Thank you very much for this precision, do you think it would be possible to avoid any alert resulting from a BIOC rule by using a correlation rule because I see that we can define a calendar?
Thanks in advance
01-05-2023 10:08 PM
Hi @S-LEGOUGE ,
Avoiding a BIOC rule to get a hit and generate an alert can happen in 3 ways only:
Correlation rule is another mechanism of creating alerting rules as per your choice on the basis of XQL queries and scheduling the XQL to run for a time frame in a particular period.
Hope this helps!
Please mark the answer "Accepted as Solution" if it does
Regards
01-06-2023 12:10 AM
Hello @Neelrohit ,
Thank you very much for this explanation and that answers my question.
Thank you again and my best wishes for 2023 😉
Regards,
Sebastien
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!