Assigning a group to a modified rule will not take effect
The following steps will reproduce this issue on the QRadar User Interface:
Click the Offenses tab
On the right hand side, click Rules
Double click on one of the system rules
Remove it from it's Group, and click Finish
Remove it from the Group and click Finish it now becomes a Modified Rule
Edit the same rule and try to add it back to the Group and click Finish
Notice that the Rule does not get assigned to the Group
QRadar 7.1 and higher
Resolving The Problem
To assign the Rule to a Group without reverting back to System rule:
Select the Rule that is not assigned to a Group
From the Action menu, select Assign Groups
Select the Group you want to assign the rule to. Click on Assign Groups.
Where do you find more information?
Was this topic helpful?
16 June 2018