Reapply lookup rules
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
4 hours ago
hi all,
I am trying to understand how/when certain rules are processed as I don't seem to have a stable solution at the moment. It could be a state setting I am overlooking in the process so any help appreciated.
For arguments sake I am using the manual import Excel functionality. Narrowed down to the one rule I am testing.
I have added a new lookup rule based on a script which works correctly when a Vulnerability is imported into SN.
The rule works as expected; when an existing CI is found it is matched.
For the other discovered items I have added test CI's after import to verify the rule, this doesn't seem to work 100%.
When I select a DI and press "Reapply" it's as though I haven't selected anything. No progress shown nor items to process.
When I change a rule and press "Apply changes" it seems to see that a DI should be processed but does nothing, no matching takes place.
I also tried to add logging to my lookup script but this doesn't seem to work, is that correct? No logging possible?
Maybe I am overlooking something in terms of processing. I have looked into the docs and seem to be following what should be an easy process.
I am testing this on Zurich in my PDI but have seen similar behaviour on Yokohama at the client
Any help with debugging/troubleshooting this or pointers to additional docs appreciated.