Hello Sniffer Folks,
In light of today's bad rule event I've discovered that many of you are
not aware of the rule-panic feature.
The rule panic feature has been built in to the Message Sniffer engine
for many years now, and I suppose is used so rarely that folks have
forgotten about it.
The feature allows you to render any single rule inert immediately
without disrupting anything else in the system. So, it could have been
used to mitigate this event without taking more drastic measures.
Here is a link to the QA article about the rule panic feature:
http://www.armresearch.com/Documentation/QA/ltrulepanicsgt-628138610.jsp
Best,
_M
--
Pete McNeil
Chief Scientist
ARM Research Labs, LLC
www.armresearch.com
866-770-1044 x7010
twitter/codedweller
#############################################################
This message is sent to you because you are subscribed to
the mailing list <sniffer@sortmonster.com>.
This list is for discussing Message Sniffer,
Anti-spam, Anti-Malware, and related email topics.
For More information see http://www.armresearch.com
To unsubscribe, E-mail to: <sniffer-...@sortmonster.com>
To switch to the DIGEST mode, E-mail to <sniffer-dig...@sortmonster.com>
To switch to the INDEX mode, E-mail to <sniffer-in...@sortmonster.com>
Send administrative queries to <sniffer-requ...@sortmonster.com>