Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: File Integrity Monitoring - So many events generated for a single file copy - How can I reduce?

$
0
0

I have had the same issue with various clients.  It's different for every single client as they all have different audit policies.  Playing with the correlation time is the only way.

 

This is something I used for a client in looking for an file open (ignore the last line with the HR Admin).  Note the correlation time as 6 events within 2 seconds which worked for one client.  Another client required 4 events within 8 seconds.

1.PNG


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>