Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

LEM Portscan rule

$
0
0

Hi all,

 

I have a question based on LEM portscan conditions. See attached snapshot for guidance.

I want to create a portscan rule which will ignore posrtscan activities originating from public IP's, but the destination should be on my internal network.

I want to detect external public IP's performing portscan activities in my internal network.

see attached screenshot to correct me.


Viewing all articles
Browse latest Browse all 5911

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>