Creating and Debugging Custom Rules Part 1 An Interesting Windows Example

preview_player
Показать описание
Link to a Box folder with a file with an index of the most recent videos, go to the second page and look for a file named Security Intelligence Tutorial, Demos & Uses Cases Version XXX.pdf
Рекомендации по теме
Комментарии
Автор

Good evening Jose! Thank you for the great content yet again. Can you tell me how you were able to "grey-out" the Custom Properties with a value of N/A in the Event Information screen(9:45)?

mfwyatt
Автор

Can you also show us in reports can we also get contributing rules along with the main rule which is triggering the offense. Is it possible to track those ?

There are certain offense where three rule conditions are matching and those other 2 rules are contributing the events.

Kindly let me know.

harshamangipudiDa
Автор

Hi Jose,
Could you make a rule for terminated accounts login so we have a reference set where we maintain terminated accounts which is updated on daily basis.

We created that reference set based on user removed events of AD. But we still observing success logons or failed logons of logon type 3 which are due to stale connections because of active sessions on those machines when the user who left didn't log off correctly.

Could you show us how we can eliminate those.

harshamangipudiDa
Автор

Sir can you make a video on how to forward Solarwinds Orion Network Performance Monitor logs to QRadar ?

sidss
Автор

how to create usercreated.log file or it's is by default

realitystuffs
visit shbcf.ru