Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jeremy_Boselly
Participant

What field name do you need to include to have LEA return the rule uid of an inline layer rule when a hit occurs?

I'm trying to be able to identify via LEA when an inline rule is being hit.  Currently LEA is only returning the rule uid of the Parent rule.

For example if you had a policy that looked something like:

Rule 1  Action: Inline_Layer_1 

Rule 1.1

Rule 1.2

Rule 1.3

I'd consider Rule 1 the parent rule and Rule 1.1, 1.2, 1.3 the child rules.

Let's say that Rule 1 and Rule 1.1 were hit.

Currently via LEA we are getting the rule uid of Rule 1.  However we're not getting the rule uid of Rule 1.1.  So we can tell how many hits an entire Inline policy is getting (which equals the number of hits of Rule 1), however we're unable to tell via LEA which of the Inline rules are being utilized.

Since you have to tell LEA what fields to include in the data it sends, what identifier do we need to utilize to get LEA to send the rule uid of a child inline rule when hit.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events