Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Filter assistance handling multiple accounts targeting one system, and one account targeting multiple systems.

$
0
0

You can't really do these things directly in a filter as filters don't give you the correlation time options that you have when creating rules.  What you could do is create rules that match these items and have the rules infer an event.  Then create filters to look for these inferred events.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>