on ‎2018 Aug 22 12:05 PM
Iam looking for a description of why specific events are classed as critical and what those Logs record exactly.
I haven't been able to find any in the Forums or elsewhere on the Internet.
Does anyone know where I can find something?
Request clarification before answering.
My reply definitely comes very late though your query reads very familiar to me. SAL alerts are not always carrying a realistic severity scoring. Often singular alerts are harmless, only when put in context with other events (not necessarily logged in the audit log!) a series of actions unfolds an exploit. PM me in case you require intelligence to be put into your audit logging...
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| User | Count |
|---|---|
| 41 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.