Create alert within working time
I would like to monitor our system with condition:
If there are no authentication log (success or fail) in working time (<7h and >19h) => alert
I try to create filter but it not allow to set filter with "event time" like this.
How can I create alert with this condition?
Currently, RSA enVision does not have capability to do this. But there is a workaround.
You can create a normal rule, create a new view with the rules you want during the time frame as mentioned.
Start the view at 7h and stop the view at 19h. This can be achieved with the scheduled tasks. There are commands to start and stop view using scripts (I could not find at this moment) which you can use.