Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Rule triggers went it is not suppose to trigger

$
0
0

A couple of issues. There is a Group inside a Group. It is effectively a single group. The innermost group is joined by an OR logic. It should be AND. The outermost group logic is AND. Since there is only 1 group member (the inner group), the AND or OR really doesn't matter

 

You rule should look like below

 

LEM-Rule-75689.png

 

Also, for future reference, the correlations section of the rule definition can be equally validated using your filters. You can create a new filter in the MONITOR screen and mimic the Correlations part of the Rule definition in the Conditions part of the Filter editor, and save the filter. Then choose the 'send to nDepth' menu option, and search over a custom time frame to validate your search criteria.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>