Open engechas opened 10 months ago
@engechas good afternoon. I did not quite understand this post. Are you saying that after creating a custom rule, that all the pre-built rules are no longer finding alerts anymore?
@eirsep , can you please confirm if this is an issue after the bug fixes
What is the bug? Creating a custom detection rule, then a detector for that rule before creating any other detectors will prevent findings from being generated for all detectors.
How can one reproduce the bug? Steps to reproduce the behavior:
What is the expected behavior? Findings should still be generated when a custom detection rule is used in the initially created detector
What is your host/environment?
Do you have any screenshots? If applicable, add screenshots to help explain your problem.
Do you have any additional context? When a detector is created with a default rule first, then a second detector is created with a custom rule, findings are generated. It looks specific to the first detector using a custom rule.