2013-05-04
11:50 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Need to Create a Rule for device not sending logs for more than 1 hour in RSA Envision
Hi All,
Can anyone help me to write a correlation rule for the device not sending logs for more than 1 hour. I already have rule for device not sending logs for more than 4 hours, but the client requirement is that he wants the alert for the devices not sending logs for more than 1 hour.
Any help would be greatful.
Regards,
Samad M
4 Replies
2013-05-05
03:01 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2013-05-05
03:47 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Areeb,
Thanks for the info.
Would be greatful if you can share the html file for the same.
Thanks,
Samad
2013-05-05
03:58 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2013-05-05
04:04 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Thanks Areeb...I will Check this and update.
