New systems added in network
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Addition of multiple new systems in the network.
Severity
Critical
Rule Requirement
Criteria
Action1: actionname = "new_device_in_port" | timewindow 10m | groupby ALARM_SOURCE having COUNT > 3 select Action1.timewindow.ALARM_ID,Action1.timewindow.ALARM_MESSAGE,Action1.timewindow.ALARM_SOURCE,Action1.timewindow.ALARM_CATEGORY,Action1.timewindow.ALARM_SEVERITY,Action1.timewindow.ALARM_TRIGGER_TIME,Action1.timewindow.ALARM_EVENT_TYPE
Detection
Execution Mode
realtime
Log Sources
ME Applications


