Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: SEM / LEM rule creation basics

$
0
0

Sounds right.

 

Take a simple rule, logon failure. If you specify the event type, but nothing for source/destination machine, etc, it will apply to every machine/group.

 

If you want to limit it to a specific group, you need to add that into the rule correlation.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>