Filter alarms for LogRhythm
Setting filtering criteria for alarms after you have mapped fields helps you determine which alarms should be ingested into the SIR application. Filtering alarms helps you significantly reduce the number of alarms you ingest when the alarm profile is activated.
Vorbereitungen
Role required: sn_si.admin
Warum und wann dieser Vorgang ausgeführt wird
Use the filtering conditions at the bottom of the mapping form to filter out specific
alarms or limit ingestion to only alarms that meet certain field-level criteria.
Filtering significantly reduces the number of alarms you ingest once the alarm
profile is activated. Use filtering to ingest a manageable quantity of alarms that
your Security Operations Center (SOC) staff can support.
Hinweis:
The following example
shows a default filter setting in which Alarm
status-does-not-contain-Closed is the default setting. This
filter only pulls active alarms, and this setting reduces the number of pulled
alarms. The following steps illustrate how to add another useful filter which
includes only alarms with the highest severity or priority values.
Prozedur
Nächste Maßnahme
The next step is to preview your mapped fields on the security incident. See Previewing the security incident with mapped LogRhythm alarm values.