4. Manually Submit an NE to Enclave (ES)
To configure, see the Automatic Submission section of the Installation Guide.
Why should I submit Notable Events to a TruSTAR enclave? |
|
Cases where user may prefer manual submission to automatic submission. |
|
Required fields | he Notable Event, when converted to a Python dictionary, needs to contain a field named "_time". |
Performance Steps.
Click the Actions carat at the far right of a Notable Event to display the Actions menu ![]() Click Run Adaptive Response Actions. The Adaptive Response Actions dialog box appears. | |
In the Adaptive Response Actions dialog box, select TruSTAR - Submit. ![]() The TruSTAR - Submit action's config dialog box will appear. | |
In the TruSTAR - Submit action's config dialog box, select the settings you'd like to use. ![]()
| |
Click Run to submit the Intel Report. A popup window provides confirmation that the report has been submitted. |