IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: How To Track If a Custom Rule Is Being Used

App Control: How To Track If a Custom Rule Is Being Used

Environment

  • App Control (Formerly CB Protection): All Supported Versions

Objective

To determine if a custom rule is still actively being used

Resolution

For File Creation Control Rules
  1. Under Rules > Software Rules > Edit the "Approve Write" rules and check the "Send Approval Event" box.
  2. Rule hits will now be shown in the console by searching in Reports > Events for Subtype = File Approved (Custom Rule)

For Execution Allow and Trusted Path Rules
  1. For every rule you are wanting to track, create a "Execution Control - Report" rule with the exact same parameters immediately above (i.e. next lower rank number) your Allow Execute or Trusted Path rule.
  2. Rule hits will now be shown in the console by searching in Reports > Events for Subtype = Report Execution (Custom Rule)

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-14-2021
Views:
1311