Skip to content

Q: How to best exclude false positives that are not fully specified through the Message field? #29

@furrnace

Description

@furrnace

How to best exclude false positives that are not fully specified through the Message field?

Example of log messages generated when vulnerability scanners such as OpenVAS are running:

MODULE:
LogScan
MESSAGE:
Suspicious Log Entry found
ENTRY:
..."GET /dotcms/html/portal/login.jsp HTTP/1.1" 200 8506 "-" "Mozilla/5.0 [en] (X11, U; OpenVAS-VT 22.7.3)" 

The thor false positives filter is just using the Message field value, and I would assume that this then filters ALL suspicious log entry findings, which would be too much. Is there a way to filter simultaneously on the Message AND on the Entry field? Or what would be a suitable solution?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions