THWACK Tuesday Tip :: How to Quickly Identify Suspicious Network Behavior With Intuitive Dashboards

FEATURED EPISODE: 
How to Quickly Identify Suspicious Network Behavior With Intuitive Dashboards
February 18, 2020

Log and event data are a boundless and valuable resource for identifying suspicious network activity and stopping potential breaches. However, analyzing lines and lines of text-based data can make this resource more trouble than it's worth. In this video, we'll explore the different ways you can customize log data in an easy-to-understand and visual dashboard in Security Event Manager to help turn it into something you can act on.
Parents
  • Another thing about dashboards... if you haven't added the new KPI widget to your dashboard it's great to watch the Oldest Stored event occurred time, Logs/Data used storage percentage, and Logs/Data used storage.  Now that I have my appliance setup correctly it's not blowing up with the snapshots anymore and aging off the oldest correlated events correctly.  There are two settings in CMC you have to set to the same amount so it won't allow the appliance to fill up.  diskusageconfig and dbdiskconfig are the two I think if I'm remembering correctly.  I had to open a case to get it straightened out.  My appliance hasn't run out of space yet.  Commvault was using snapshots and eating up some of my datastore normally used by the SEM appliance.  I reduced the snapshots some and set the two settings in the CMC and now it's stable.

Comment
  • Another thing about dashboards... if you haven't added the new KPI widget to your dashboard it's great to watch the Oldest Stored event occurred time, Logs/Data used storage percentage, and Logs/Data used storage.  Now that I have my appliance setup correctly it's not blowing up with the snapshots anymore and aging off the oldest correlated events correctly.  There are two settings in CMC you have to set to the same amount so it won't allow the appliance to fill up.  diskusageconfig and dbdiskconfig are the two I think if I'm remembering correctly.  I had to open a case to get it straightened out.  My appliance hasn't run out of space yet.  Commvault was using snapshots and eating up some of my datastore normally used by the SEM appliance.  I reduced the snapshots some and set the two settings in the CMC and now it's stable.

Children
No Data
Thwack - Symbolize TM, R, and C