Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: DNS Server Audit - Email alert

$
0
0

The correlation appears to be looking for a "HostIncident," which can only be generated by the LEM itself.  Unless you have another rule that looks for those DNS events under the appropriate taxonomy, like an ObjectAudit or other event calls, and makes a host incident, your rule will probably never fire.  Seeing how the SEM is normalizing the event so the appropriate correlations can be chosen will help.


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>