4 Replies Latest reply on Apr 21, 2015 8:30 AM by robert_dearbytes

    How can i import and export same event to a specific data source for testing a rule that i created?


      Hi all,


      I am kind of new to McAfee SIEM and working on getting used to this tool. I have created a windows rule that looks for any account changes on specific group of devices. Eventually i have also created an alarm based on this SIGNATURE ID


      However, i do not know if the alarm is working fine or not. May i request any assistance on creating some test event or how can i import/export and sample event that i can replay for testing.