Posted By
Moises Monge
Fri January 10, 2020 10:45 AM
Found In
Egroup:
IBM Security QRadar
\
view thread
Hello, SIM Generic do consume license. I will suggest evaluating the SIM Generic Events rather than just dropping them, these are events coming from log sources that couldn't be autodiscovered. You can collect these events in raw format break them by the source (IP address or hostname) evaluate if ...
|