cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

Correlation over a period of time

Jump to solution

I have two events I am trying to correlate together, for the example we will say that one is administrative login and the other is a change in the firewall.
I would like it to be configured so that if an event showing admin login has occured in the last 12 hours and then there is a change in the firewall, I'd like to get a notification for it.
Currently I set the time window to 12 hours, I am not sure if this will grant me the required result.
Thanks in advance for any support

Labels (3)
1 Solution

Accepted Solutions
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Correlation over a period of time

Jump to solution

Hi, 

it seem's good.

just confirm that there's a "AND" gate for both events.

 

Best regards

David

1 Reply
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 2 of 2

Re: Correlation over a period of time

Jump to solution

Hi, 

it seem's good.

just confirm that there's a "AND" gate for both events.

 

Best regards

David

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator