I would like to know if DDOS Content pack rules work as it was meant to be if I update its data source from flow to Events?
#DOS Rules condition (Default is flow)
They should work as long as you have the events being processed by the ESM with the correct information. However, you will need to copy the rule as every update will change the rules back.
Download the new ePolicy Orchestrator (ePO) Support Center Extension which simplifies ePO management and provides support resources directly in the console. Learn more about ePO Support Center
2821 Mission College Blvd.
Santa Clara, CA 95054 USA
Consumer Support | Enterprise Support | McAfee.com
Legal | Privacy | Copyright © 2019 McAfee, LLC