There are 5 authentication servers that report to different Event Processors. There is a requirement to generate an Offense if there are 5 consecutive failed logins detected across any of the 5 Event Processors.
Which type of rule should the analyst create?
Global rules These rules use the Any domain modifier and run across all tenants.
Currently there are no comments in this discussion, be the first to comment!