For "IP Address matching" enVision checks the circuits in the Correlation Rule Logic only when the IP address matching criteria is met. For "Threshold Definitions" Event thresholds can be defined in terms of the following:
A specific number of events are received within a specified time period.
The total number of events received is either greater than or less than either the selected event average or event baseline
The absence of events being received. If you normally receive a specific message and you do not receive one for a user-specified period of time, this constitutes an alert. (This threshold definition is only used for correlation statements.)
If you want to consider every event received for that message as an alert, then no threshold is set.
Each time a threshold is met within the time frame enVision issues 1 alert, and resets the event count for the threshold. For example, depending on how you set up the threshold criteria, if the threshold criteria is met 3 times during an hour, enVision issues 3 alerts.
Related Articles
Error: The system cannot locate the specified RDN 'DC=x, DC=y' in the external identity source 'example. Verify that the d… 9Number of Views SA : Using specific admin account did not get all the configuration within a service 6Number of Views Account reviews do not create change requests to revoke items when certain configuration options are defined in RSA Identi… 42Number of Views In RSA Identity Governance & Lifecycle, what is the difference between an account's Last Collected Date and Last Collected… 35Number of Views Access Fulfillment Express (AFX) for RSA Identity Governance and Lifecycle 6.9.1 P15 and above resends auto-fulfillment re… 32Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Governance & Lifecycle 8.0.0 Installation Guide How to Detect and Resolve Stalled Workflows and Workpoint Issues in RSA Identity Governance & Lifecycle RSA Identity Governance & Lifecycle - Access Certification whitepaper RSA Authentication Manager 8.2 reports 'Unexpected error during command com.rsa.admin.GetPrincipalNestedGroupsCommand exec…