cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Correlation over a period of time

Jump to solution

I have two events I am trying to correlate together, for the example we will say that one is administrative login and the other is a change in the firewall.
I would like it to be configured so that if an event showing admin login has occured in the last 12 hours and then there is a change in the firewall, I'd like to get a notification for it.
Currently I set the time window to 12 hours, I am not sure if this will grant me the required result.
Thanks in advance for any support

Labels (3)
1 Solution

Accepted Solutions
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Correlation over a period of time

Jump to solution

Hi, 

it seem's good.

just confirm that there's a "AND" gate for both events.

 

Best regards

David

1 Reply
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Correlation over a period of time

Jump to solution

Hi, 

it seem's good.

just confirm that there's a "AND" gate for both events.

 

Best regards

David

More McAfee Tools to Help You
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • Visit: Business Service Portal
  • More: Search Knowledge Articles
  • ePolicy Orchestrator Support
  • The McAfee ePO Support Center Plug-in is now available in the Software Manager. Follow the instructions in the Product Guide for more.