I have two events I am trying to correlate together, for the example we will say that one is administrative login and the other is a change in the firewall.
I would like it to be configured so that if an event showing admin login has occured in the last 12 hours and then there is a change in the firewall, I'd like to get a notification for it.
Currently I set the time window to 12 hours, I am not sure if this will grant me the required result.
Thanks in advance for any support
Solved! Go to Solution.
Hi,
it seem's good.
just confirm that there's a "AND" gate for both events.
Best regards
David
Hi,
it seem's good.
just confirm that there's a "AND" gate for both events.
Best regards
David