Our default is to log everything and create additional actions for specific items.
for example, we have rules for Windows login errors, Cisco events, application errors, etc. Most of these start pretty broadly then get tuned over time.
Our default is to log everything and create additional actions for specific items.
for example, we have rules for Windows login errors, Cisco events, application errors, etc. Most of these start pretty broadly then get tuned over time.