Keep standard alerts when migrating to RBA #26
Unanswered
ZachTheSplunker
asked this question in
Q&A
Replies: 1 comment
-
The standard or "traditional" correlation searches can still provide value on high fidelity, low volume alerts. An excellent example is if you need to be notified immediately if a specific PowerShell command is run in your environment. These standard alerts work best if they are directly actionable. If they are not and they produce a lot of noise, this could be a good candidate for a Risk Rule in RBA. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
When you implement RBA, do you still keep standard alerts or are all of the Correlation Searches moved to RBA? And if you keep some standard alerts, why?
Beta Was this translation helpful? Give feedback.
All reactions