cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
68
Views
0
Helpful
0
Replies

Cisco Secure Network Analytics - .CSE Rule Exclude Payload information

aleksta9826435
Level 1
Level 1

Hi everyone,

Having some .CSE rules when high amount of data Is leaving a internal network. Having alot of false positives related to this. 
And I'm wondering If It's possible in some way to exclude a specifik "Subject Payload" field?

That "Subject Payload" Is visibile due to my SAL logging that I have. 

From a regular "flow search" I can exclude  the "Subject Payload" field under, 
--> Advanced Connection Options
--> Payload

But this Is not available under,
--> Policy Management
--> Custome Security Events

Thanks

0 Replies 0