Which tuning methodology guideline can the analyst use to tune out this traffic?

An analyst reviewed an active offense that was many attackers, generating many events in the same category, targeting many systems. Upon further analysis, the analyst determined that the traffic from the attackers is legitimate and should not contribute to the offenses.

Which tuning methodology guideline can the analyst use to tune out this traffic?
A . Edit the building blocks by using the Custom Rules Editor to tune the specific event.
B . Use the Log Source Management app to tune the category.
C . Edit building blocks by using the Custom Rules Editor to tune the category.
D . Use the False Positive Wizard to tune the specific event.

Answer: C

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments