In GuardDuty, how can we create a filter to exclude findings marked as [SAMPLE]

0

I used "Generates sample findings" in GuardDuty settings to test the integration with AWS Security Hub and the SNS notifications configuration.

It works great, but now I have a long list of findings marked with [SAMPLE]. I tried to configured a Filter criteria to exclude all [SAMPLE] findings, without any success.

Is it possible to create Filter criteria to exclude all [SAMPLE] findings in GuardDuty ?

gefragt vor 9 Monaten889 Aufrufe
4 Antworten
0
Akzeptierte Antwort

Exporting should work. I just tried exporting and downloading (I had 164 samples) it worked without any problem. Maybe try a different browser?

AWS
beantwortet vor 9 Monaten
0

The problem with [SAMPLE] findings is that information is not available in the Console in order for the filter to work. The only place that information is available is Sample findings have a value of "sample": true in the additionalInfo section of the finding JSON details, but that does not help with filtering either. One thing you can do is to select all [SAMPLE] findings from Console and archive them. That way you will not see them in the current view anymore.

AWS
beantwortet vor 9 Monaten
0

Thanks for your suggestion, but it doesn't resolve my case. Here are additionnal infos.

All [SAMPLE] findings are already archived. I want to provide a list of all security events that occured in the past to an auditor. It means I want to include active and archived findings but exclude [SAMPLE] because they are not relevant the scope of the audit. I also tried the export functions to filter the JSON on "sample" value state, but when I click on download button it hangs indefinitely and I am not able to export the file. For your information I only have 249 findings (all samples) to export.

beantwortet vor 9 Monaten
0

I retried after your post and exporting and downloading are working now int the same browser I had issue, I can't explain the cause of the issue previously.

I can have a workaround with exporting feature. But I thing it could be great to have to filter Sample finding in the Console.

Thanks for your help!

beantwortet vor 9 Monaten

Du bist nicht angemeldet. Anmelden um eine Antwort zu veröffentlichen.

Eine gute Antwort beantwortet die Frage klar, gibt konstruktives Feedback und fördert die berufliche Weiterentwicklung des Fragenstellers.

Richtlinien für die Beantwortung von Fragen