Forum Discussion
Cole_McDonald
28 days agoProfessor
If written as a datasource, counts of events per timeframe can also self clear and you end up with an historical graph of "normal" to boot. That can help identify cadences to the issues if there are any. Spike at 3am every morning, etc. I use a few X events / 5 minute 'Sources I've made to track quantity aberrations in logs. Specifically, Security:4625 with all it's glorious substatuses. That can show graphically when a service account has failed... and when and where brute force attacks are happening in a Windows environment.
DanN
27 days agoNeophyte
Is there a datasource example in LM that you would recommend using to replicate your idea?
Related Content
- 2 months ago
- 9 months ago
- 8 months ago
- 11 months ago