Showing results for 
Show  only  | Search instead for 
Did you mean: 
Level 8
Report Inappropriate Content
Message 1 of 3

Alarm on deviations from baseline

Hi everybody!

I'm SIEM ESM 9.3.2 user. How can I create an alarm on deviations from baseline for total event count?

For example, I want monitoring the deviations shown by a view "Event Distribution Bound to Event Summary".

A single alarm for each data source does not work, because the view "Event summary" (with baseline) doesn't shown the missing events (but only the events detected).

In your opinion, which is the best practise for monitoring malfunctions (lack of data) of the data sources?

Thank you

2 Replies
Level 8
Report Inappropriate Content
Message 2 of 3

Re: Alarm on deviations from baseline

Ok, I've th key!

System Properties -> Alarms -> Condition -> Type: Deviation From Baseline


Re: Alarm on deviations from baseline

Can you provide more details on how you configured this? Which query / filters did you use to accomplish this?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community