Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Issue - Rule Creation Logic vs nDepth Logic

$
0
0

Ok thank you, I think that answers the question.  It is unfortunate that we can't perform manual searches against our historical data in LEM for the purpose of testing correlation rules.  Is this a feature that may be added at some point? Where can I submit a feature request?

 

Also, the primary logic in the rule is "Any Alert.ExtraneousInfo = *subtype=ips*" - the rest of the rule consists of negating events that I do not want to see trigger the rule.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>