I am not sure that I use right category so I am sorry in advance.
Is it possible to add exceptions to the rule using Detection as Code from Elastic directly in the rule file (.toml) without creating a Shared Exception list. I would appreciate any help and examples with this since I have no information regarding this topic.
Apologies for the delay here. I’m tracking down answers to a few questions on my end so that I can get you an accurate response. I’ll aim to get back to you by tomorrow (PST) morning latest. Thanks for your patience.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.