Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

Flood traffic

$
0
0

My question is in reference to the Denial of service attack. If there is a Denial of service attack on the monitored device than how LEM will react to that traffic? Will it log all the events of DOS attack or specific? Any filtering done at agent level in forwarding filtered DOS attack events?

 

Asking this as I think if there is a DOS attack on monitored device and if all events are stored on SIEM then SIEM storage space will run out quickly.


Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>