In GuardDuty, how can we create a filter to exclude findings marked as [SAMPLE]

0

I used "Generates sample findings" in GuardDuty settings to test the integration with AWS Security Hub and the SNS notifications configuration.

It works great, but now I have a long list of findings marked with [SAMPLE]. I tried to configured a Filter criteria to exclude all [SAMPLE] findings, without any success.

Is it possible to create Filter criteria to exclude all [SAMPLE] findings in GuardDuty ?

asked 9 months ago805 views
4 Answers
0
Accepted Answer

Exporting should work. I just tried exporting and downloading (I had 164 samples) it worked without any problem. Maybe try a different browser?

AWS
answered 9 months ago
0

The problem with [SAMPLE] findings is that information is not available in the Console in order for the filter to work. The only place that information is available is Sample findings have a value of "sample": true in the additionalInfo section of the finding JSON details, but that does not help with filtering either. One thing you can do is to select all [SAMPLE] findings from Console and archive them. That way you will not see them in the current view anymore.

AWS
answered 9 months ago
0

Thanks for your suggestion, but it doesn't resolve my case. Here are additionnal infos.

All [SAMPLE] findings are already archived. I want to provide a list of all security events that occured in the past to an auditor. It means I want to include active and archived findings but exclude [SAMPLE] because they are not relevant the scope of the audit. I also tried the export functions to filter the JSON on "sample" value state, but when I click on download button it hangs indefinitely and I am not able to export the file. For your information I only have 249 findings (all samples) to export.

answered 9 months ago
0

I retried after your post and exporting and downloading are working now int the same browser I had issue, I can't explain the cause of the issue previously.

I can have a workaround with exporting feature. But I thing it could be great to have to filter Sample finding in the Console.

Thanks for your help!

answered 9 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions