One of the "ah-ha" moments with LEM for me was when one of the support techs explained how LEM uses an event taxonomy (the policy). Understanding that is key to writing filters and correlations; before that I was really struggling. I still struggle with it at times but understanding that has made a huge difference.
↧