defenxor / dsiem

Security event correlation engine for ELK stack
GNU General Public License v3.0
435 stars 100 forks source link

It's not rule #335

Open Atanon opened 3 years ago

Atanon commented 3 years ago

Hello,

Can we create the rule not within the Plugin_Sid values? (example !SRC_IP or !Custom_Data1)

Our goal is to generate an alarm if a user connecting with vpn does not connect to a server within 10 minutes. So is it possible to generate an alarm in case of a non-existent event?

SridarSri commented 2 years ago

+