Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Incidents created when manager logs in as root for cron

$
0
0

Your solution will not give the desired effect. You have all your conditions in a correlation box set to OR (yellow right edge). So, if any of these conditions are met it will apply. That means the "DetectionIP not equal to *swi-lem* " will meet this even if the DestinationAccount isn't administrator, root, or guest.

 

I believe this will accomplish that.

 

Lem Rule 2.JPG

 

The right edge is set to AND (Blue). Meaning that both groups must meet the condition for the correlation to be true. The (DestinationAccount is equal to administrator, root, or guest) AND the (DestinationIP is not equal to your LEM appliance).


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>