What is an approach to tuning a "noisy" rule, that is, a rule that generates too many offenses?

What is an approach to tuning a "noisy" rule, that is, a rule that generates too many offenses?
A . Determine whether the rule matches too many conditions in the traffic.
B . In the offense output, scroll down and review the "Excessive" flags.
C . Confirm that the rule is enabled.
D . Use the QRadar Pulse app to map noisy offense output.

Answer: A

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments