This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

CIDR Notation for LEM rule

Hi,

I would like create a rule in LEM that will give me an alert whenever it detects any logins failed or successful from external IP (Public IP). I plan to use the filter below (sample only for 10.0.0.0/8) but I think it would be more accurate if I can use CIDR notation but not sure if LEM currently supports it. Any inputs will be very much appreciated.

pastedImage_0.png

Thanks a lot!

Neil