How to create a Rule in ArcSight ESM

Описание к видео How to create a Rule in ArcSight ESM

If you have found what I do interesting and if you would like me to continue you can check the link below 😊

https://buymeacoffee.com/nextgensiemt...

How to create a Rule using ArcSight ESM.
This is just a simple example how to create a Standard Rule - Brute Force Login Attempt.

First step - Build your Conditions using the Common Condition Editor, using the Boolean Logical Operators (And; OR; NOT)
Second step- Define Aggregation (how events will be aggregated)
Third step- Activate trigger (how many times the rule will fire if events occure?) and specify an Action (perform automatically something)

Enjoy, like, share and subscribe for more videos!

Комментарии

Информация по комментариям в разработке