Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: I see the alerts, but my rule doesn't fire

$
0
0

Ok cool.

 

Can you edit the correlation rule to look like this - i.e. add the Provider *USB* condition and also adjust the response window to 5 minutes? Can you also make sure to click Activate Rules on the main Build - Rules page?

 

Capture.JPG


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>