Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

LEM Portscan rule

$
0
0

Hi all,

 

I have a question based on LEM portscan conditions. See attached snapshot for guidance.

I want to create a portscan rule which will ignore posrtscan activities originating from public IP's, but the destination should be on my internal network.

I want to detect external public IP's performing portscan activities in my internal network.

see attached screenshot to correct me.


Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>