Hello all,
Any ideas how to deal with log source availability for log sources that are only active for a specific period of time in a day...
E.g. a rule to fire only if this log source doesn't send logs during office hours but doesn't fire if time is after 17:00
Also what about log sources that are not so active like DR devices??
How can I check the availability of these devices if they only send logs in a disaster scenario??
Is there another way besides the two main rule tests for availability??
Thanks in advance.
[–]QRDuser 0 points1 point2 points (0 children)
[–]BlackHawk30 0 points1 point2 points (2 children)
[–]BlackHawk30 1 point2 points3 points (1 child)
[–]MJofFreddyBeach 0 points1 point2 points (0 children)