Hi All, I was wondering if it's possible to added time based exceptions to detection rules?
An example would be with some of the current detection rules, they get triggered during system patching. Ideally it would be nice to add an exception for systems during a specific time frame that they will be patched, so alerts won't be detected then. I wasn't able to find anything regarding this searching around so figured I'd ask here.
Note: I'd like to add it as an exception rather than part of the filter or query, so that comments could be appended to the exception so people know why its there and how to change it.