Hi Team,
So there is a requirement.
Can we have a rule in SecOps SIEM that will trigger whenever there is a log stoppage from that particular log source (product & vendor) for a period of 1 or 2 hours?
Custom Use Case
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
