cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Multi-Column Watchlist

Hi.

I need to create correlation rule which react when user logon from new IP address (for him). Number of users - 700+. Each of them has 1-2 source logon IP. 

For example I have whitelisted pairs like:

  • User1 - 10.1.1.2
  • User1 - 10.1.1.3
  • User2 - 10.1.1.2

and want to get correlation event when User2 logon from 10.1.1.3 or 10.1.5.1 for example. Number of users is 700+.

Can you advise me please how to realize this using McAfee ESM 11.2 (or 11.4) without creating very long correlation rule with hundreds of AND+OR elements?

4 Replies
lratcliffe
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 5

Re: Multi-Column Watchlist

Could you implement a custom parser rule and parse a new field which is a combined string "username-ipaddress" then compare that with a combined string watchlist?

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Multi-Column Watchlist

custom parser rule

Yes. I thought about this. But there was the question (I am new in ESM) - if I create additional parsing rule, will the original parsing rule be processed (for example for windows logon event 4624)? Or parsing engine try to apply all rules for all events in this device type - not only the first matching? Or I must  rewrite original parsing rule to add field "user+ip"?

lratcliffe
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 5

Re: Multi-Column Watchlist

All enabled parsing rules are processed, so you would need to disable the existing parser rule to use your new rule.

You had not stated before this was for Windows events, this adds an additional challenge.  To use custom parsing rules for Windows events you need to send them via syslog - see https://community.mcafee.com/t5/Security-Information-and-Event/Parsing-WMI-Events/m-p/458052#M3586 for an implementation another customer used.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Multi-Column Watchlist

Thanks. I will try later. 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community