Ah, yes. This is in fact why we chose to disable those rules by default in future/more recent versions of LEM.
A few threads that might help:
, , and .Ah, yes. This is in fact why we chose to disable those rules by default in future/more recent versions of LEM.
A few threads that might help: Re: LEM: Trying to tone down the noise, Re: Unsusual or Suspicious Traffic, and Usefulness of these Internal Rules fired from LEM Appliance.