IBM QRadar: Use Case Manager app
Rules
- when the event matches this AQL filter query
- cria Rule que é disparado através do resultado de um query AQL
Testes negativos:
- when the event(s) have not been detected by one or more of these log source types for this many seconds
- when the event(s) have not been detected by one or more of these log sources for this many seconds
- when the event(s) have not been detected by one or more of these log source groups for this many seconds