# Detection Rule Exceptions "is one of", comma in value

**URL:** <https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [May 11, 2021, 8:01pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738 "2021-05-11T20:01:17Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [May 11, 2021, 8:01pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/1 "2021-05-11T20:01:17Z")

</div>

Hi All,

I'm trying to add an exception to a detection rule. This exception is intended to be an `is one of` rule, that excludes a number of ISPs. However, I am running into an issue some of the ISP names contain a comma, but everytime I try to add it, it is split into two values as commas for `is one of` are handled as a list. Example ISP: `Google, LLC`

Is there a way to actually add the value with a comma to an `is one of` exception? I wasn't able to find any existing issues/docs regarding this.

I tried:

- Escaping the comma `Google\, LLC`
- Double quoting the string `"Google, LLC"`

All tests didn't work and ended with the same result.

I can sometimes work around this as occasionally the exception area will recommend the correct value with the comma and add it, but this doesn't always work, and requires a few attempts when it does. Resulting in a lot of time in order to add the value.

Note: I know that I can add this as a separate exception that is just an `is`, but would prefer to have everything in a singular exception.

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 1:33am UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/2 "2021-05-12T01:33:03Z")

</div>

You would be best of using Adding Known IP Ranges for google [TheWatchList/google.txt at main · SCS-Labs/TheWatchList (github.com)](https://github.com/SCS-Labs/TheWatchList/blob/main/Cloud_Provider_Lists/google.txt) for a example and then add it as a list to that specific exception.

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [May 12, 2021, 1:43pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/3 "2021-05-12T13:43:35Z")

</div>

Google was just an example, the issue is there are a quite a few ISPs which can have a comma in their names, and I think trying to track at the IP level is generally more cumbersome instead of just excluding the name, you would need to keep track of and exclude many different subnets. (If you're aware of a good way to do this though, I would be interested in investigating further).

This also doesn't really solve the problem for other cases where you have a value with a comma in it that you want to exclude in a `is one of` clause.

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 6:24pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/4 "2021-05-12T18:24:08Z")

</div>

Or you can use a wildcard

```auto
Google* LLC

```

or just like this

```auto
Google*

```

---

<div class="post-metadata">

**Author:** ![yctercero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yctercero/32/68560_2.png) [@yctercero](https://discuss.elastic.co/u/yctercero)\
**Post date:** [May 12, 2021, 6:33pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/5 "2021-05-12T18:33:58Z")

</div>

Hey @BenB196 !

Thanks so much for bringing this to our attention. I have gone ahead and opened up a bug ticket for this that you can follow [here](https://github.com/elastic/kibana/issues/99975).

Have you tried using large value lists for this use case? You can find some information on it in the [docs](https://www.elastic.co/guide/en/security/current/detections-ui-exceptions.html), but this could be useful in this case where you may be continually adding values. Using a large value list you can then easily share this list of values across rules.

Best,  
Yara

---

<div class="post-metadata">

**Author:** ![austinsonger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/austinsonger/32/78994_2.png) [@austinsonger](https://discuss.elastic.co/u/austinsonger)\
**Post date:** [May 12, 2021, 8:17pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/6 "2021-05-12T20:17:20Z")

</div>

@BenB196

Here is example of how I use value list.

**Upload Value List Pop Up**

 ![](https://us1.discourse-cdn.com/elastic/original/3X/6/1/613d2c5e55476645dd701db2d70aa8d5a56fda65.png)

**Exception**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/0/e089ff65a522c5294bbb57b6d30f263a2f9bbe12.png)

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [May 12, 2021, 8:30pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/7 "2021-05-12T20:30:45Z")

</div>

@austinsonger @yctercero thanks, completely forgot that exception lists were a thing in the UI. I'll look into using them for the larger lists.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 9, 2021, 8:31pm UTC](https://discuss.elastic.co/t/detection-rule-exceptions-is-one-of-comma-in-value/272738/8 "2021-06-09T20:31:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
