Size: a a a

2020 February 21

Z

Zer🦠way in MaxPatrol SIEM
Капибара
К NADу прикрутить, не?
источник
2020 February 22

M

Mikhail in MaxPatrol SIEM
virars
да, я это понимаю, просто у меня в списках источников есть неуправляемые, есть ли у них логирование и вообще какой в этом смысл...)))
Читай по определению, не управляемый - значит нет возможности управлять и прописать syslog сервер...😂
источник

BO

Balqess Odat in MaxPatrol SIEM
Hi everyone 👋🏻

Just a question  🙋🏻

Firstly I have  a database activity monitoring solution   and I wanna  to push the  alerts (events)  to Maxpatrol SIEM  through syslog but  the  task didn't complete,   help 👩🏻‍💻 🌸
источник

E

EИ0Ʇ in MaxPatrol SIEM
Balqess Odat
Hi everyone 👋🏻

Just a question  🙋🏻

Firstly I have  a database activity monitoring solution   and I wanna  to push the  alerts (events)  to Maxpatrol SIEM  through syslog but  the  task didn't complete,   help 👩🏻‍💻 🌸
Hi! What`s the trouble? Writing normalization for syslog information messages is too easy.
источник

MH

Mohammed Houssani in MaxPatrol SIEM
Do we have to create normalization rule?
источник

E

EИ0Ʇ in MaxPatrol SIEM
Mohammed Houssani
Do we have to create normalization rule?
Sure, you can look it up in the knowledge base
источник

💎

💎 in MaxPatrol SIEM
Alsalam ealaykum everyone
источник

MH

Mohammed Houssani in MaxPatrol SIEM
We are having a trouble finding English manual can you please share the steps
источник

RS

Roman Sergeev in MaxPatrol SIEM
Create new rule
1. got a sample of raw syslog event
2. install and run SDK GUI (.NET windows application)
3. write your rule and test it on your samples
источник

RS

Roman Sergeev in MaxPatrol SIEM
Install new rule
1. clone siemdb database in PTKB
2. set it as installable
3. set up validation sdk for new db
4. create new empty rule and copy rule text from SDK GUI
5. install content from PTKB to SIEM
источник

MH

Mohammed Houssani in MaxPatrol SIEM
Many thanks😊
источник

RS

Roman Sergeev in MaxPatrol SIEM
look for ideas of parsing on rules from vendor in PTKB
there are a thousands of them
источник

RS

Roman Sergeev in MaxPatrol SIEM
i've sent you devguide in English
источник

MH

Mohammed Houssani in MaxPatrol SIEM
Thank you great
источник

E

EИ0Ʇ in MaxPatrol SIEM
For self-wrote formulas we strongly recommend validate them before installing into SIEM
источник

MH

Mohammed Houssani in MaxPatrol SIEM
Good advise thanks
источник
2020 February 23

BO

Balqess Odat in MaxPatrol SIEM
hi everyone

just a question , how can i filter the events by time "i need the syntax that determine specific event at specific time"  help!
источник

RS

Roman Sergeev in MaxPatrol SIEM
In query (event viewer) or in rule (filter clause in event declaration block)?
источник

BO

Balqess Odat in MaxPatrol SIEM
источник

RS

Roman Sergeev in MaxPatrol SIEM
Time field is not applicable for where clause. Try to narrow down time filter in top left position (22-24 February)
источник