Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: correlation rule for windows login

$
0
0

Can you share a printscreen with us of what you've set up in the rule conditions?

I would suggest first thing first -> create a filter with the exact same conditions that you have in your rule, then see....what events are appearing in that filter? It could be that it's not the right condition mix. But actively seeing it in a filter (where youll see events coming in real time) will help see what events those conditions catch.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>