Size: a a a

2020 February 28

E

EИ0Ʇ in MaxPatrol SIEM
Переслано от virars
дичь
источник
2020 February 29

BO

Balqess Odat in MaxPatrol SIEM
good day everyone  ,,
источник

BO

Balqess Odat in MaxPatrol SIEM
источник

BO

Balqess Odat in MaxPatrol SIEM
in regards of this screenshot , how could i limit the number of incidents triggers
источник

RS

Roman Sergeev in MaxPatrol SIEM
Go to event viewer. Group events with non null correlation_name by correlation_name. First one will be your rule.
источник

RS

Roman Sergeev in MaxPatrol SIEM
Go to the rule text in PTKB by clicking on its name
источник

RS

Roman Sergeev in MaxPatrol SIEM
Some rules have options for configuring or whitelisting
источник

BO

Balqess Odat in MaxPatrol SIEM
well , thanks roman
источник

RS

Roman Sergeev in MaxPatrol SIEM
what rule caused a problem?
источник

BO

Balqess Odat in MaxPatrol SIEM
we created a TeamViewer rule
источник

RS

Roman Sergeev in MaxPatrol SIEM
and it triggers on every connect/packet?
источник

BO

Balqess Odat in MaxPatrol SIEM
yes ,
источник

RS

Roman Sergeev in MaxPatrol SIEM
you have to consume duplicates
in your version (22+ will provide different and better solution) i recommend something like that:
create table list  (for correlations)
first column and a key should be your host (ip, fqdn, whatever)
set record ttl for 1 hour (specific interval is up to you)
check for record existence and create alert/incident only on it's absence
insert to list on emit
источник

MH

Mohammed Houssani in MaxPatrol SIEM
Hello Guys
источник

MH

Mohammed Houssani in MaxPatrol SIEM
am trying to open the Siem using https from out side the network
источник

MH

Mohammed Houssani in MaxPatrol SIEM
but after creating the needed DNAT rules
источник

MH

Mohammed Houssani in MaxPatrol SIEM
the login page redirect me to the internal ip address
источник

MH

Mohammed Houssani in MaxPatrol SIEM
shall i add a parameter to the core XML file ?
источник
2020 March 01

ММ

Максим Максимович... in MaxPatrol SIEM
Mohammed Houssani
shall i add a parameter to the core XML file ?
Try to set hostadress parameter to hostname instead of ip. The hostname should be resolved inside the network you are trying to access it.
источник

BO

Balqess Odat in MaxPatrol SIEM
Good day  everyone,
Hope all doing well,

I have misunderstanding of some definitions , so we need  to clarify it  and  how could we  deal with it  

The difference between these and how I can use it  or when?!

-Normalization formulas
-Enrichment rules
-Corroboration rules
-localization rules
-Aggregation rules



Also the difference between below and when I could use it  :'

-macros
-tabular list
-event field schema

??
источник