In GuardDuty, how can we create a filter to exclude findings marked as [SAMPLE]

0

I used "Generates sample findings" in GuardDuty settings to test the integration with AWS Security Hub and the SNS notifications configuration.

It works great, but now I have a long list of findings marked with [SAMPLE]. I tried to configured a Filter criteria to exclude all [SAMPLE] findings, without any success.

Is it possible to create Filter criteria to exclude all [SAMPLE] findings in GuardDuty ?

질문됨 9달 전888회 조회
4개 답변
0
수락된 답변

Exporting should work. I just tried exporting and downloading (I had 164 samples) it worked without any problem. Maybe try a different browser?

AWS
답변함 9달 전
0

The problem with [SAMPLE] findings is that information is not available in the Console in order for the filter to work. The only place that information is available is Sample findings have a value of "sample": true in the additionalInfo section of the finding JSON details, but that does not help with filtering either. One thing you can do is to select all [SAMPLE] findings from Console and archive them. That way you will not see them in the current view anymore.

AWS
답변함 9달 전
0

Thanks for your suggestion, but it doesn't resolve my case. Here are additionnal infos.

All [SAMPLE] findings are already archived. I want to provide a list of all security events that occured in the past to an auditor. It means I want to include active and archived findings but exclude [SAMPLE] because they are not relevant the scope of the audit. I also tried the export functions to filter the JSON on "sample" value state, but when I click on download button it hangs indefinitely and I am not able to export the file. For your information I only have 249 findings (all samples) to export.

답변함 9달 전
0

I retried after your post and exporting and downloading are working now int the same browser I had issue, I can't explain the cause of the issue previously.

I can have a workaround with exporting feature. But I thing it could be great to have to filter Sample finding in the Console.

Thanks for your help!

답변함 9달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠