cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
466
Views
0
Helpful
5
Replies

Disabled rule still triggering alerts?

astroman
Level 1
Level 1

Anyone experienced this?

I've unattached a rule from an active module/policy for the group that all hosts belong to, and it's still generating alerts with the 'Rule XXX - No longer enforced on ClientX'. It's been happening for over a week...

Also disabled the rule entirely and it's still generating alerts...

I've reset the agents, etc.

5 Replies 5

wyley.johnson
Level 4
Level 4

Have you verified that the agents in question have downloaded the new policies?

From the standpoint of checking polling times, lowering polling times down to 1 minute, etc...

Yes.

This cloned rule in question is the only rule that has been modified in the policy.

How about download times? When you make a change to the policy you should see the agent actually record when it downloaded the last change on the agent GUI.

Alternatively, you should be able to create a new agent kit without that rule/policy and apply it to the host.

tsteger1
Level 8
Level 8

You might have another rule stepping on this one. That's been my experience with this behavior

Try disabling the original rule and/or detach one of the hosts from all groups except .

Is it all hosts or just some? When clients can't poll fast enough they will enforce old rules but that should only be temporary.

I've disabled the original rule, and am still getting alerts on the original, but with the 'rule xxx no longer enforced on clientxxx'.

I've detached all of the hosts from the original group, added them to the custom group, and All Windows. That's it.

I'm working on the issue again this afternoon, and will post updates...