December 2017
Intermediate to advanced
410 pages
11h 5m
English
One of the very challenging aspects is to detect the abnormal activity among thousands of unexpected event occurrences in a large enterprise.
Many times it happens that the system administrator will just configure the output of logs to be sent to the log monitoring solution and just leave it like that.
Ideally, there should be proper documents which say, what action on Alert N and what action on Alert Z should be taken. Thus, alert and action should be corresponding with each other and should be approved by the higher authorities within the organization.
This can be further understood with the help of the following table, which contains a sample scenario and actions to be taken if a particular ...
Read now
Unlock full access