Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Help eliminate Alert Email Overload

$
0
0

I agree, it won't eliminate them - but once you're IN the chain of events there's a small chance it might reduce them.

 

LEM isn't deterministic unless you tell it to, so unless you specify the EventA.DetectionTime < EventB.DetectionTime thing they could happen in any order, so you could actually have an online that came in BEFORE the offline that cancels it out (or doesn't). That 60 minutes is a sliding window before/after the first event that starts the clock.

 

What you described is definitely the ideal case, and I'm still duking it out with the development team as to whether it's a bug or just an artifact of the behavior of the rule. I've found a couple of other NOT EXISTS bugs myself which don't work the way I'd expect so there's still a pretty solid chance it's not working as intended either.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>