Trying to get rid of an useless Wazuh Alert that is spamming me
Hey guys, I manage a large size organization Wazuh, and I have been getting thousands of alerts regarding outdated Firefox version's CVEs spread around my company, since I have hundreds of machines, this is just trash alerts for me, and I would like to find a way to reduce their threat level from 13 to, for example, 5.
Is there any way I can get all alerts that fit the following description:
data.vulnerability.package.name: Mozilla Firefox (x64 pt-BR)
To be lowered down to level 5?
I tried many rules in local_rules, all of them generated by AI, but none of them seem to work