Forum Discussion
Cole_McDonald
13 days agoProfessor
If written as a datasource, counts of events per timeframe can also self clear and you end up with an historical graph of "normal" to boot. That can help identify cadences to the issues if there are any. Spike at 3am every morning, etc. I use a few X events / 5 minute 'Sources I've made to track quantity aberrations in logs. Specifically, Security:4625 with all it's glorious substatuses. That can show graphically when a service account has failed... and when and where brute force attacks are happening in a Windows environment.
- DanN13 days agoNeophyte
Is there a datasource example in LM that you would recommend using to replicate your idea?
Related Content
- 8 months ago
- 2 months ago
- 7 months ago
- 10 months ago