Skip to content

Duplicate EventIDs #505

Open
Open
@PhilOrdo

Description

@PhilOrdo

Root cause presently unknown, but occasionally a few signatures will somehow be assigned the same EventID. This is not validated until attempting to push signatures on the deployment box.

The current solution is to change the signature category then change it back so the next available EventID for the category is assigned.

Example:
Screenshot 2025-01-10 at 1.08.19 PM.png
Changing the newest of each rule to EC then back to MC assigns them EventIDs 5002064 and 5002065 respectively.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions