bhdresh / Dejavu

DejaVU - Open Source Deception Framework
https://www.camolabs.io
Other
393 stars 97 forks source link

Feature Request - Ability to ignore certain addresses from triggering alert #41

Closed BenUhlig closed 2 years ago

BenUhlig commented 2 years ago

We have a few systems (Zabbix, Tenable.SC, etc. that will scan the network and I see those triggering alerts. Is there a way to configure this to ignore these known systems so it does not trigger an alert?

TIA

bhdresh commented 2 years ago

Yes, it is possible,

1) To filter the search : Apply filter as below from Threat Analysis -> Active Attacks -> Search Filter

filter

2) To filter the notification : Apply filter as below from Threat Analysis -> Manage Notifications -> New Alert

Selection_001

BenUhlig commented 2 years ago

Thank you... this makes sense now. I appreciate the info!