Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Prioritization of Log Inspection rules with the same sort order and match pattern

    • Updated:
    • 21 Jan 2019
    • Product/Version:
    • Deep Security 11.0
    • Platform:
    • N/A N/A
Summary

Identify how the Log Inspection (LI) rule is chosen if there are multiple rules with the same sort order that match a single log.

Details
Public

If there are multiple LI rules with similar sort order that match to a single log, Deep Security will follow the LogInspectionRule ID. The LI rule with the lower LogInspectionRule ID will be chosen.

Note that the LogInspectionRule ID is different from the Rule ID in the customized rule properties. The LogInspectionRule ID is the rule's ID in the database, which you can view in the exported XML of a rule.

Export a rule to XML file to view its LogInspectionRule ID

For example, if you created three (3) custom rules with same content, their LogInspectionRule ID will still be different because of their creation sequence. Below are the sample rules (2, 3, and 3-new). Given the scenario that all these three rules simultaneously exist, the events will always hit the Rule 2.

Rule 2

Rule 2

Rule 3

Rule 3

Rule 3-new

Rule 3-new

Premium
Test Now
Internal
Rating:
Category:
Configure
Solution Id:
1102898
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.