menu
techminis

A naukri.com initiative

google-web-stories
source image

Socprime

2w

read

311

img
dot

Image Credit: Socprime

IBM QRadar: How to Create a Rule for Log Source Monitoring

  • You can create a custom rule to generate an offense or send notifications when logs stop coming from any log source.
  • Go to the Rules Section: Navigate to Offenses > Rules. Click Actions > New Event Rule.
  • Define the Rule Conditions: Steps: In the rule editor, click on Test Group and choose from the drop-down list Log Source Test. Search for and select parameter 'when the event(s) have not been detected by'. Set the 'of these log sources' and 'this many' (e.g., 10 minutes (set in seconds)).
  • Add Response to the Rule: Under the Response tab, choose the response(s) to make when an event triggers this rule.

Read Full Article

like

18 Likes

For uninterrupted reading, download the app