In GuardDuty, how can we create a filter to exclude findings marked as [SAMPLE]

0

I used "Generates sample findings" in GuardDuty settings to test the integration with AWS Security Hub and the SNS notifications configuration.

It works great, but now I have a long list of findings marked with [SAMPLE]. I tried to configured a Filter criteria to exclude all [SAMPLE] findings, without any success.

Is it possible to create Filter criteria to exclude all [SAMPLE] findings in GuardDuty ?

已提问 9 个月前889 查看次数
4 回答
0
已接受的回答

Exporting should work. I just tried exporting and downloading (I had 164 samples) it worked without any problem. Maybe try a different browser?

AWS
已回答 9 个月前
0

The problem with [SAMPLE] findings is that information is not available in the Console in order for the filter to work. The only place that information is available is Sample findings have a value of "sample": true in the additionalInfo section of the finding JSON details, but that does not help with filtering either. One thing you can do is to select all [SAMPLE] findings from Console and archive them. That way you will not see them in the current view anymore.

AWS
已回答 9 个月前
0

Thanks for your suggestion, but it doesn't resolve my case. Here are additionnal infos.

All [SAMPLE] findings are already archived. I want to provide a list of all security events that occured in the past to an auditor. It means I want to include active and archived findings but exclude [SAMPLE] because they are not relevant the scope of the audit. I also tried the export functions to filter the JSON on "sample" value state, but when I click on download button it hangs indefinitely and I am not able to export the file. For your information I only have 249 findings (all samples) to export.

已回答 9 个月前
0

I retried after your post and exporting and downloading are working now int the same browser I had issue, I can't explain the cause of the issue previously.

I can have a workaround with exporting feature. But I thing it could be great to have to filter Sample finding in the Console.

Thanks for your help!

已回答 9 个月前

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则