As the title says. We don't want to disable reporting on things, because we do want to be able to perform correlative analysis, and to reconstruct events if necessary. But with the amount of events we're logging, literally every system on our network is perpetually escalated, and even if we work through and de-escalate something, it's back on the board in a day or two. Any way to log these events without them triggering escalations, or do we just give up on the protection workspace totally and let our SIEM do the lifting?
Solved! Go to Solution.
Give up on protection workspace and let siem do the lifting. You can't configure PW for specific events or anything like that.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Give up on protection workspace and let siem do the lifting. You can't configure PW for specific events or anything like that.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA