How to create a Rule in ArcSight ESM

preview_player
Показать описание
If you have found what I do interesting and if you would like me to continue you can check the link below 😊

How to create a Rule using ArcSight ESM.
This is just a simple example how to create a Standard Rule - Brute Force Login Attempt.

First step - Build your Conditions using the Common Condition Editor, using the Boolean Logical Operators (And; OR; NOT)
Second step- Define Aggregation (how events will be aggregated)
Third step- Activate trigger (how many times the rule will fire if events occure?) and specify an Action (perform automatically something)

Enjoy, like, share and subscribe for more videos!
Рекомендации по теме
Комментарии
Автор

Great man it simple and easy to understand

sivasakthivel
Автор

Very nice video 👍👍👍 but have one doubr why we add fields under the threshold, like we already assign all the field during creation of filter

securityguy-zx
Автор

Can you please make a video on correlation rule

ShubhamSingh-pwg
Автор

Great Video thanks tsvetelin, If possible please make a video for join rule and some advance rules

vatsranjan
Автор

Could you please tell me how send this alert into email.

Example: suppose, as per video you entered 4 failed attempts. I want to receive 4 emails alerts.

How? Where do i go to set the option.

brpsingara
visit shbcf.ru