Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: New Requirement for my team, we have to identify users that are concurrently logged into numerous devices.

$
0
0

You could use Rules occurence settings in new UI (advanced correlation in older Flex UI) to specify that userName/sourceAccount have to be same in the alerts AND source IP of the event should differ. Set "Set time when a rule won't trigger actions after rule was true" (Re-Infer TOT - in Flex) as well to not fire rule multiple times during few seconds.


Viewing all articles
Browse latest Browse all 5385

Trending Articles