SIEM Alerting - toggle workstations on/off/separate timing
M
Matt Timm
It would be great to have SIEM log failure alerting separate for Endpoints (event logs) and network equipment/other connectors. Use case: I'd like to know if a sonicwall stops sending logs to a syslog connector within 4 hours of failure, but don't want to be alerted if a workstation is offline and not sending logs. It would be great to have separately controlled thresholds/per source with a default for that type of source available as well.
L
Les McNair
This would be very helpful. To tag on, a per source setting as well as a per organization setting or override would a nice touch. We need more options than the current 1,4, and 8 hours. For always-on infrastructure this works, but for Windows Event Logs we would like to extend that threshhold to 24 or even 48 hours for select organizations.