Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM Event Severity Filter

$
0
0

This is what I have to trap events with the severity levels higher than 4. Pretty simple. But then you have to realize what information is being pulled into LEM in your case. I have some firewalls reporting to it and those have different severity levels of their own that do not match the levels assigned to them by LEM.

 

In many cases you can be very specific about the events you want to be informed based on their severity levels, if LEM allows that event's severity information to be used in the condition for a rule\filter.

 

severety levels.JPG


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>