Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM rule for four specific alerts...help

$
0
0

You have a lot of ORs there, so effectively any ONE of those things will trigger your rule to fire. Are your other events getting generated from services being stopped on your Avantis server (ServiceStop.DetectionIP=*avantis*)?

 

Should those inside OR groups actually be AND?


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>