Managing exceptions
Note
This feature is in the Preview stage. To get access, contact tech support
This section describes how to create exceptions, manage their settings, and perform basic operations with them.
Getting started
The Yandex SIEM section will appear in the Cloud Center interface as a Security Deck module after the access request is approved.
You need the ycem.editor role to use the service.
Creating an exception from a correlation rule
To create an exception from a correlation rule:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Correlation rules.
- In the rule's row, click
and select Create exception. - Under Conditions, add one or more
key = valuepairs for events that should not trigger the rule. - Under Parameters, fill in the required Name field, and, optionally, the Description field.
- Click Save.
The associated rule will be filled in automatically.
Creating an exception from the exceptions section
To create an exception from the exceptions section:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Exceptions.
- Click New exception.
- From the list that opens, select the correlation rule you are creating the exception for.
- Under Conditions, add one or more
key = valuepairs for events that should not trigger the rule. - Under Parameters, fill in the required Name field, and, optionally, the Description field.
- Click Save.
Editing an exception
To edit exception settings:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Exceptions.
- In the exception row, click
and select Edit. - Edit the fields as needed.
- Click Save.
Disabling an exception
To disable an exception:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Exceptions.
- In the exception row, click
and select Disable.
A disabled exception changes its status to Inactive and will no longer apply when processing events.
Resetting changes
To reset the changes you made to the exception to the last deployed version:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Exceptions.
- In the exception row, click
and select Reset changes.
All unsaved changed will be canceled. The exception will reset to the last deployed configuration.
Deleting an exception
To delete an exception:
- Go to Security Deck
. - In the left-hand panel, select Yandex SIEM.
- Navigate to Exceptions.
- In the exception row, click
and select Delete. - Confirm the deletion.
Warning
Exception deletion is irreversible. All exception settings will be cleared.