IBM QRadar: Use Case Manager app

From Wiki
Revision as of 09:11, 15 January 2025 by Ebasso (talk | contribs) (→‎Rules)

Rules

  • when the event matches this AQL filter query
cria Rule que é disparado através do resultado de um query AQL

Testes negativos:

  • when the event(s) have not been detected by one or more of these log source types for this many seconds
  • when the event(s) have not been detected by one or more of these log sources for this many seconds
  • when the event(s) have not been detected by one or more of these log source groups for this many seconds

Ver também