Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: LEM Rule for Multiple Failed Logins using multiple account

$
0
0

You will probably want to use Advanced Correlations.  Assuming that your rule is something like this, click the highlighted gear button:

 

2014-03-25 08_44_26-SolarWinds Log and Event Manager Console.png

Then you can create a correlation like this:

2014-03-25 08_45_02-SolarWinds Log and Event Manager Console.png

That means that all five events (in my example) have to come from the same DetectionIP to trigger the rule.

 

I hope that helps!


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>