Active List With Dynamic TTL

Active List With Dynamic TTL

The CyberSIEM team has developed a tool that makes taking care of these exclusions as simple as creating an Active List.

ArcSight Rule Action – Telegram Message

ArcSight Rule Action - Telegram Message

Any conversation with the bot has a unique Chat ID, the bot will need this ID to know where to send the message. Of course, you can use the same bot for a few conversations, and send different alerts to each group.

Rules based on aggregate SUM

Rules based on aggregate SUM

How to create a data monitor which will collect the information from the last X time, and sum the quantity and create a rule that use the audit events of the Data Monitor to check if the value is more than a specific threshold.

Contain from Active List

Contain from Active List

Have you ever wanted to create a rule that has the ‘Contain From Active List’ condition in ArcSight?