Skip to content

🐞💿 Suppression gives 400 Bad Request #473

@timguyuk

Description

@timguyuk

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

Installing Selks 10 I have the system up and running. I have a internal server that is hit by authorised traffic but ET SCAN Potential SSH Scan picks it up. no problem I add the authorised src ips to suppression accept I cant in selks 10. If I try and add from the hunting Dashboard I get a 400 Bad Request. Within https://x.x.x.x/rules/rule I can no longer click on the comments to see the suppression. I can goto history there are entry's but no information other than ip 172.18.0.2? If I goto https://x.x.x.x/rules/ruleset/1/ I can see suppressions but if I click on the id number i get "Server Error (500)"

Expected Behavior

No response

Steps To Reproduce

  1. Goto hunting dashboard
  2. Filter by Source IP
  3. Policy Actions / Supress
  4. Default Rule Set / Comments
  5. Submit
  6. 400 Bad Reques

Anything else?

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions