Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Alert for devices not logging?

$
0
0

In Microsoft style, I'm going to start this response with:

 

  • Never use the "AnyAlert" group in a rule, as it will cause the LEM to chew through memory like a boss.
  • Never extend the correlation time too much, as longer correlation times will cause the LEM to chew through memory like a boss.
  • This example is really likely to totally destroy a LEM in production. Don't do this.

 

Now, how you might do this:

2015-01-30 07_44_59-SolarWinds Log & Event Manager.png

So, I agree with Nicole: there isn't a good way to do this, but this might be a way to do it.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>