- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Creating Rule for Event Increase of Device/Device Group
- If the baseline is for a devicegroup will it look at cumulative baseline for the entire devicegroup?
- Is there an easy way to do the baseline for each device without creating seperate OR statements for each device?
- How is hourly average calculated?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
When you said that the rue seems to trigger on source IP baseline, was that because you are using a filter for the source IP addresses?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Can you please post the entire rule XML? It will make it easier for us to evaluate what is going on that way.
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks...How do you know that it is triggering based on source IP address and not on the number of events? There are 201 message IDs that are in Network.Connections and Network.Denied Connections. Is it just that you keep getting one message from an individual source IP that for some reason has lots of activity making it appear that it is triggering on source IP?
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
The attached rule should be implementing the logic you described, As Paul said earlier it could be that you are receiving alerts from only one IP address
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Remember that you only see the last message that caused the alert to be generated. What this means is that you went up over the 60% mark more than once in the hour. Let's say the baseline starts at 100...it means it hit 160 and then it hit 176, etc. I have always found the baselining to be somewhat odd to implement...it should settle down over time and then you should see less number of alerts being generated in an hour until you restart the view or alert and then it will do something similar again.
Paul
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
- If the baseline is for a devicegroup will it look at cumulative baseline for the entire devicegroup?
- Is there an easy way to do the baseline for each device without creating seperate OR statements for each device?
- How is hourly average calculated?
