cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Configure Alarm for devices that not sending logs to SIEM

Greetings!

Dear Friends,

I have some data sources (around 100) that giving logs to SIEM in every an hour.

Few days agao some systems (3 may be) not sending logs to SIEM.

How can i configure an Alarm that triggers when any devices does not send logs? 

Thank You!

Yours Sincerely,
Syed Irfan Naseer
2 Replies
Reliable Contributor sssyyy
Reliable Contributor
Report Inappropriate Content
Message 2 of 3

Re: Configure Alarm for devices that not sending logs to SIEM

There an alarm for inactivity. Try that, it never worked for me btw.

Re: Configure Alarm for devices that not sending logs to SIEM

You can do Device Health and Device Failure alerts.  I think the device health triggers on flags, and if a data source were to go inactive it should flag the receiver.

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community