Schedule and retrieve LogRhythm alarms
After you preview the security incident with the LogRhythm alarms that you have selected and mapped, you are ready to schedule alarm retrieval. After you complete this step, the alarm profile is ready to be activated.
Antes de Iniciar
Role required: sn_si.admin
Por Que e Quando Desempenhar Esta Tarefa
Scheduling permits you to modify the scheduling and the types of alarms selected for retrieval. You filter the alarms you ingest based on a date range or on specific alarm IDs. With this step, you determine whether you want to ingest historical alarms, and how often you poll for future alarms that match the alarm profile configuration.
Procedimento
O que Fazer Depois
After you configure the Ongoing Alarm Ingestion and One Time Retrieval details, the next step is to Additional options for LogRhythm alarms.