Skip to content
Discussion options

You must be logged in to vote

Yes, that's why I mentioned you would need to have no tuning applied to see that. There isn't a field in the rule that specifies whether it is enabled by default or not.

It really comes down to your network and what you want to alert on.

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
4 replies
@cm-ops
Comment options

@security-companion
Comment options

@cm-ops
Comment options

Answer selected by security-companion
@security-companion
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
2 participants