Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: HP Printer Status (port 5226) PortScan triggered events in LEM?

$
0
0

Assuming you're using one of our template PortScan rules, the criteria is just looking for 10 packets where:

 

2015-11-13 08_41_20-SolarWinds Log & Event Manager.png

So if the printer or client send data to the same IP but on different ports trying to establish a pipe, that may cause false positives.  You could modify the rule to ignore source and/or destination ports of 5226.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>