Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: Recognizing A Sequence of Events

$
0
0

It's hard to answer this precisely because I don't know what devices are sending logs and what the LEM will classify those logs as when normalizing them.  Therefore, this is a general example, and may or may not work for your specific example.

 

I think you'd end up with a rule that looks something like this:

 

2017-05-08 08_21_45-SolarWinds Log & Event Manager.png


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>