Open for Voting

Create IDS Event Class in LEM

Currently LEM distributes IDS events into approximately 180 event classes, including high volume classes such as TCPTrafficAudit, UDPTrafficAudit, and ICMPTrafficAudit. This makes it very difficult to filter out IDS events for monitoring and alerting, and places a tremendous strain on the rule engine. It would be much simpler and less resource intensive on the LEM system if there was simply an IDS event class for these purposes.