Disabled YARA sources are still used #327
Labels
accepted
This issue was accepted, we will work on this at some point
bug
Something isn't working
ui-frontend
Describe the bug
I've recently tried a new set of YARA rules, but after a few days I decided that it looks too big and causes timeouts. I wanted to pause using it until I find time to better select useful rules from it. I decided to disable the update source, but I'm still getting hits from this ruleset (after a day since disabling it).
To Reproduce
Steps to reproduce the behavior:
Expected behavior
When I disable a source, I do not expect related rules to be used at all. However, it looks like disabling YARA rules disables just updating it.
My theory is that disabled rules are ignored from generating the new rules file for the service etc., but already generated files are still present and never deleted.
Screenshots
If applicable, add screenshots to help explain your problem.
Environment (please complete the following information if pertinent):
Additional context
The text was updated successfully, but these errors were encountered: