Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Brief duration event correlation

$
0
0

It would probably look like:

 

NewDomainMember EXISTS

AND DeleteDomainMember EXISTS

AND NewDomainMember.DestinationAccount = DeleteDomainMember.DestinationAccount

within time/response window 24 hours

 

(The first two lines with the EXISTS are redundant to the third but help you see what's going on.)

 

The downside of this is you expand your global response window to whatever that period is (24 hours), which means your appliance might hold onto more data longer in memory. To test it I'd set the time period short and see how it works.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>