- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Correlation rules
Hi people,
today I have created a rule stating that if any new devices onboard or deleted from the existing list To get alerted on that. I was confused to select which event category I need to select. (I selected the system crypto. But that didn't work. I deleted a device and added the same device still my rules is not working. When I din that it asked me to restart INC alert and collector alert service I did that but still no luck could anyone please help me to sort out this
thanks in advance for help
regards
shri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi
Are you looking for any new devices that show up.
NIC024 does that. You can use that in a View, and set up you output.
I don't know about ones that disapear, however, you can use the correlated report NIC023 in a View.
This will show you when a monitored device stops sending data.
I hope this helps
Thanks
Tim
