Hello Martin,
You have to locate this rules:
Device Stopped Sending Events (Firewall, IPS, VPN or Switch)Device Stopped Sending Events
then you can customize the seconds count in each one.
In my personal experience i suggest you to separate the log sources in different groups and create your own rules with different counts as every log source type and log source has difference performance and they has different "dead times" to send event to Qradar, for example, separate the linux servers and Windows servers log sources in different groups and create 2 different rules to each one with different counts.
Regards,
------------------------------
Johan Lopez
------------------------------
Original Message:
Sent: Mon June 21, 2021 11:29 AM
From: Martin Schmitt
Subject: Log source has stopped emitting events
I have Events with the Eventname "Log source has stopped emitting events" and i like to adjust the time until that event will occure but i can not find the timer for that event. Anybody knows how to tune it?
------------------------------
Martin Schmitt
------------------------------