cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Analytic BIOC Rules, right click open in query builder, informational severity not available

L3 Networker

We have a support ticket open for "informational" analytic BIOC rules that are not alerting.

These do not show up in the incidents or alert table, but the number of alerts in that column has more than 0

Support has indicated there is not a way to view the hits of the rule

Does anyone know a way to view these analytic bioc rule alerts

 

When viewing normal bioc rules, you can right click and open in query builder.

This option isn't available when looking at analytic bioc rules.

Is there a place or way to view how the rule is structured...what the xql query is? 

 

Who Me Too'd this topic