Skip to content
User Guide

Govern → IDS Policy

IDS Policy is the control center for intrusion detection. It is a tab on the Govern page — visible to anyone whose role can view sensors; making changes additionally requires your license to include the IDS Sensors add-on (without it, the create/edit buttons show a lock). It has two sub-views selected by the toggle in its toolbar:

  • Routing — decide what happens to each alert your sensors raise.
  • Rulesets — choose where detection rules come from and build the ruleset your sensors apply.

Routing

Routing decides what happens to each IDS alert as your sensors raise it. It is an ordered list of rules evaluated top-to-bottom; the first rule that matches wins.

How an alert is handled

Every non-suppressed alert is stored (and shown in IDS Alerts) regardless of the rule; notify and log are additional routing on top:

flowchart LR
  sensor["Passive IDS sensor<br/>watches traffic"]
  stream["Alerts streamed to the core"]
  sensor --> stream --> rules{"IDS policy rules<br/>first match wins"}
  rules -->|suppress| dropped["Dropped · not stored"]
  rules -->|otherwise| stored["Alert stored<br/>shown in IDS Alerts"]
  stored --> anotify["notify → automation event"]
  stored --> alog["log → forwarded to your SIEM"]

What you can do

  • Add rules that match incoming alerts and choose how each is handled.
  • Reorder rules — order decides which rule wins.
  • Enable or disable a rule without deleting it.
  • See how often each rule has matched.
  • Delete a rule.

Fields

Each rule has any number of selectors and three independent action toggles. Every selector is optional; an empty selector means any.

FieldMeaning
SensorsMatch only alerts from these sensors.
LocationsMatch only alerts from sensors in these locations.
SeveritiesMatch only alerts at these severities.
CategoriesMatch only alerts in these categories.
Signature IDs (SIDs)Match only these specific signature IDs.
Notify / Log / SuppressThe action toggles — what to do on a match (see below).

The three action toggles:

  • Notify — raise an automation event, which your playbooks can route to email, a webhook, or any other action.
  • Log — forward the alert to your external logging / SIEM destinations.
  • Suppress — drop the alert entirely. Suppress is exclusive: while it is on, Notify and Log are unavailable.

Notify and Log can be combined on the same rule. A rule may also have none of the three set — a matching alert is then simply stored (and shown in IDS Alerts) with no further routing, which is also what a rule that only exists to shadow broader rules below it looks like.

Common tasks

Add a rule

  1. Click Create Rule.
  2. Set the selectors you want to match on; leave any selector empty to mean any.
  3. Flip the action toggles — Notify and/or Log, or Suppress.
  4. Click Create Rule.

Reorder rules

  1. Drag a rule by its handle to a new position.
  2. Because the first matching rule wins, place more specific rules above broader ones.

Enable or disable a rule

Toggle the rule’s switch. A disabled rule is skipped during evaluation.

Review a rule’s activity

Each rule shows its hit count, so you can tell which rules are doing the work and which never fire. Use the clear control next to it to reset the counter.

Delete a rule

  1. Click the red trash icon on the rule.
  2. Confirm.

Rulesets

The Rulesets view manages the whole detection-ruleset lifecycle in one place — where rules come from, your own custom rules, per-rule overrides, and the built versions your sensors apply. It is split into a left rail of four steps and a content pane showing the selected step. An orange ·N badge next to a step counts changes you have staged there but not yet published.

The four steps

StepWhat it’s for
Download RulesEnable the rule sources your sensors draw from — catalog entries (such as ET Open) or your own Custom Source URLs. Some commercial sources need a parameter or secret before they can be used.
Custom RulesAuthor your own local detection rules, layered on top of the downloaded sources.
Ruleset VersionsChoose the update mode (Auto or Manual), upload a ruleset in Manual mode, and see every built version. Each row shows its sources and size; the current one carries an Active badge, and you can Activate an older version to roll back.
Rule OverridesForce-enable, silence (disable), or reset individual catalog rules by their signature ID (SID). Search and filter by source, state, or classtype, and apply changes in bulk with Enable all / Disable all / Reset all.

The status panel

Beneath the steps, a status panel always shows where the live ruleset stands and what (if anything) is waiting to be published:

StateMeaning
Up to date (green)Your configuration matches the live ruleset. Nothing to do.
Changes pending (orange)You have staged changes that are not yet live. A Pending vs live breakdown shows Sources (+added −removed), Custom rules (+added ~edited −removed), and the number of Overrides.
Unmanaged ruleset (blue)Sensors are running a ruleset built outside this workspace. Build & publish to bring it under management.
No ruleset yet (blue)First run — no ruleset has been built. Enable sources, then build & publish to create the first one.

When a ruleset exists, the panel also shows the live version, the date it was built, and whether the mode is Auto or Manual. Two actions appear in the panel depending on its state:

  • Build & publish — shown in every state except Up to date; compiles a new ruleset from your current sources, custom rules, and overrides, then distributes it to all online sensors. In Manual mode this button is disabled; you upload a ruleset instead.
  • See what changed — shown in the Changes pending state; opens a detailed diff between your current configuration and what the live ruleset was built from, with its own Build & publish button.

Common tasks

Build & publish a ruleset (Auto mode)

  1. In Download Rules, enable the sources you want to draw rules from.
  2. Optionally add Custom Rules of your own and silence or force-enable individual rules under Rule Overrides.
  3. Watch the status panel. As you stage changes it moves to Changes pending and shows a Pending vs live breakdown; click See what changed to review the full diff.
  4. Click Build & publish. MisterShell compiles the ruleset and distributes it to all online sensors; the panel returns to Up to date.

Sensors pull and apply the active ruleset on their next check-in. Until a sensor catches up, a drift warning appears next to it on the Sensors estate.

Upload a ruleset instead (Manual mode)

  1. Select the Ruleset Versions step and switch the update mode to Manual.
  2. Click Upload tarball and choose your ruleset .tar.gz (up to 50 MB). In Manual mode, uploading is how you publish.
  3. The new version appears in the versions table with an Active badge and is distributed to sensors.

Roll back to an earlier ruleset

  1. Select the Ruleset Versions step.
  2. Find the version you want in the table and click Activate.
  3. That version gains the Active badge and is distributed to sensors on their next check-in.

Permissions

  • Read: app.sensors.read.
  • Add / edit / reorder / enable: app.sensors.write.
  • Delete: app.sensors.delete.