Implementing SSL Cert monitoring due to the new policy for Certificate renewal times, i have discovered that you cannot easily only allow SSL Expiry Events for listed servers.
As we have thousands of “internal” self-signed certs, a lot of these have expired but do not need to be re-issued.
What i’d like to be able to do is to create a “Device Group” and add in the Servers that i DO want to alert on…
using a Dynamic Rule to look for a custom “Atribute” on the device for “SSL_Monitoring” but use a “!*” rule to invert the device group.
that way this Device Group can be added into the “Suppressions” on the SSL Events.
Currently this does not work and i wold need to add Device names into the Rule manually as an inverse.
this method will work but will get very messy and will reply solely on my as the administrator to update the list, Ideally other staff should just be able to add that custom “Attribute” and the server will be added automatically and the Inverse rule would flip the logic and allow that device to alert on SSL Cert expiration.

