cancel
Showing results for 
Search instead for 
Did you mean: 
Read only

Description of critical Events in Security-Audit-Logs

0 Likes
328

Iam looking for a description of why specific events are classed as critical and what those Logs record exactly.

I haven't been able to find any in the Forums or elsewhere on the Internet.

Does anyone know where I can find something?

Accepted Solutions (0)

Answers (1)

Answers (1)

ivan-ae
Explorer
0 Likes

My reply definitely comes very late though your query reads very familiar to me. SAL alerts are not always carrying a realistic severity scoring. Often singular alerts are harmless, only when put in context with other events (not necessarily logged in the audit log!) a series of actions unfolds an exploit. PM me in case you require intelligence to be put into your audit logging...