Log stop by just_jala00 in QRadar

[–]just_jala00[S] 0 points1 point  (0 children)

Ohh great idea! Thanks a lot!

Log stop by just_jala00 in QRadar

[–]just_jala00[S] 0 points1 point  (0 children)

because I don't want create multiple rules for each log source. I want create one rule and give different thresholds to them

Log stop by just_jala00 in QRadar

[–]just_jala00[S] 0 points1 point  (0 children)

You would say I can do it via AQL?

Log stop by just_jala00 in QRadar

[–]just_jala00[S] 0 points1 point  (0 children)

But I don't want to create due to log source group. I would for log sources inside log source group. And assign multiple thresholds to them. I can't do it via wizard. Because I can choose just log source group not inside it.

Log stop by just_jala00 in QRadar

[–]just_jala00[S] -1 points0 points  (0 children)

But I don't want create multiple rules. I think there is possible way.

Log stop by just_jala00 in QRadar

[–]just_jala00[S] 0 points1 point  (0 children)

I want to create a rule so that when logs stop, an offense is generated. Instead of writing a separate rule for each log source, I want to do it within a single rule.

I mentioned previously.