FortiSIEM Discussions
MBerube
New Contributor

Import rules with event type groups

Hi,

 

I have to import rules to a production SIEM.  Many of these rules contains a eventType IN (Group@PH_SYS_EVENT_Group).

 

We have noticed those conditons are broken when imported in the new SIEM and we have to remap them manually to the event type group.

 

My question:  Is there a quicker way to make those statements working?

 

Thanks,

1 Solution
premchanderr
Staff
Staff

Hi @MBerube ,

 

Custom groups are unique to a system and upon manual import you would have to re-map them. 

 

Unfortunately no other workaround to perform bulk  re-mapping objects.

Regards,
Prem Chander R

View solution in original post

3 REPLIES 3
premchanderr
Staff
Staff

Hi @MBerube ,

 

Custom groups are unique to a system and upon manual import you would have to re-map them. 

 

Unfortunately no other workaround to perform bulk  re-mapping objects.

Regards,
Prem Chander R
MBerube

All right.  Thanks.

premchanderr

You are welcome :) 

Regards,
Prem Chander R
Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"