Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM Rule Correlations – Group vs. Individual

$
0
0

In your example, the group isn't doing anything.  The LEM rules engine actually does a lot of stuff in the background to simplify convoluted rules, so both examples are probably actually working identically in the background, so it's just cosmetic.

 

If you're going to have a lot of IPs that you're looking at, it will probably be easier to create a User Defined Group with the IPs and then us that in the rule instead of a line per IP.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>