Correlation Rules - BEST PRACTICES
"Bruno Moraes" <[email protected]>
| Newsgroups | gmane.comp.sysutils.loganalysis |
|---|---|
| Message-ID | <[email protected]> |
Dear All, Good morning. I'm study about techniques of creation correlation rules. There are many log management tools in the market with native correlation rules in the software.... I need create a list of correlation rules that isn't native in the sec tool to my environment. First Example that i thought: Create one correlation rule that alert when the users make duplicate login in the network.. What you have seen as best practices about creation of correlation rules user-defined? What are the best examples? Other example: Log Integration between firewall x ids ... Any suggestion? Many thanks for attention. Bernard _______________________________________________ LogAnalysis mailing list [email protected] http://www.loganalysis.org/mailman/listinfo/loganalysis