Submit a ticketCall us

WebinarUpcoming Webinar: How Help Desk and Remote Support Pays for Itself

Learn how help desk software can simplify ticketing management, allow you to track hardware and software assets, and accelerate the speed of IT support and service delivery. Gain insights on how remote support tools allow your IT team to maximize their efficiency and ticket resolution by expediting desktop troubleshooting, ultimately helping keep end-users happy and productive.

Register here.

Home > Success Center > Log & Event Manager (LEM) > Enable or Disable Threat Feeds

Enable or Disable Threat Feeds

Table of contents
Created by Erica Gill, last modified by Tim Rush on Jul 07, 2017

Views: 1,234 Votes: 1 Revisions: 7

Overview

This article describes how to enable  or disable Threat Feeds. LEM (versions 6.2 & newer) introduced the feature of Threat Feeds, which allow recognizing known and proven threats. Rules can make use of this data to automatically take action on Threat Feeds. 

 

Other references:

Environment

LEM 6.2 and newer

Steps

 

  1. Log onto the LEM Web or Air Console.

  2. Click Manage > Appliances.

  3. Go to the Settings tab and select or deselect Allow Log & Event Manager to detect threats based on lists of known malicious IP addresses.
    Enable Threat Feeds

  4. To verify that your Threat Feed is updating every morning, you can run the following nDepth search and look for this recurring event that comes in every morning at 3:14 AM:
    InternalInfo.EventInfo = *threat*

 

 

 

 

 

Last modified

Tags

Classifications

Public