Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM: Trying to tone down the noise

$
0
0

That should reduce how frequently the rule triggers.  The required behavior should now be that a source talks to a destination on unique destination ports at least 30 times in 10 seconds.  Which is the kind of behavior you would expect from something scanning for open ports on a box.  I would test it to make sure you like the results, tuning as necessary.  You should be able to force the rule to trigger with nmap, nessus, or something similar.

 

As far as the number of events required, I think it was 10 out of the box.  That may have been a change between versions.  You can adjust it to whatever works for your environment.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>