Hello Karl,
thank You for Your reply. The reason I let those rules active for that long was to "catch" workstations of colleagues that were away at that time, and I wanted to catch them all. That's also reason I didn't use TTL in refset, I was afraid entries would be removed before 2nd rule had time to check them. I did use IP as value type.
That said, I will definitely try Your approach, looks good, it didn't occur to me to try to use meta-events and unique value check.
Thank You for the advice.
------------------------------
Nikola Nikolić
------------------------------
Original Message:
Sent: Wed April 20, 2022 06:08 AM
From: Karl Jaeger
Subject: Rule not removing entries from reference set
Nikola
formally this looks ok but there are a few things that come to my mind. 1st of all: 7 weeks of testing thats a long time! You should see the effect of your rules after 30 minutes latest, right? I wouldnt work on a single refset. Pls detect your active machines 1st and export them after 24h. Then you import those IP adresses to your 2nd refset and remove all those not needed by your 2nd rule. This has the advantage that you can restart the process any time, use TTL based refsets and do not have to enable/disable any rules. Most of the machines should have been removed after 24h. Pls also make sure your refsets use IP type content. Another good practice is check refset entries for unique values before adding data. In order to track whats happening you should create metaevents in you rules. Pls see my examples below.
Good Luck
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
------------------------------