Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Creating an alert if source is always the same?

$
0
0

This can be accomplished with Advanced Correlation rules.  These are hiding in the rules builder behind this gear:

 

2017-03-22 10_41_51-SolarWinds Log & Event Manager.png

 

When you click on that, you'll get the option to have the LEM check if certain values on multiple events are the same or unique, so you could set it like this:

 

2017-03-22 10_42_21-SolarWinds Log & Event Manager.png

 

I've attached a rule I built that should do what you want if you want to look at this in your LEM.


Viewing all articles
Browse latest Browse all 5385


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>