Submit a ticketCall us

AnnouncementsFace your biggest database issues head-on

Our new eCourse helps you navigate SQL Server performance blocks by teaching you how to recognize and deal with the three DBA Disruptors: Performance Hog, Blame Shifter, and Query Blocker. Register today to learn how to defend your environment and fend off menacing disruptions.

Register for your free eCourse.

Home > Success Center > Log & Event Manager (LEM) > LEM - Knowledgebase Articles > Enable or Disable Threat Feeds

Enable or Disable Threat Feeds

Table of contents
Created by Erica Gill, last modified by Tim Rush on Jul 07, 2017

Views: 1,256 Votes: 1 Revisions: 7

Overview

This article describes how to enable  or disable Threat Feeds. LEM (versions 6.2 & newer) introduced the feature of Threat Feeds, which allow recognizing known and proven threats. Rules can make use of this data to automatically take action on Threat Feeds. 

 

Other references:

Environment

LEM 6.2 and newer

Steps

 

  1. Log onto the LEM Web or Air Console.

  2. Click Manage > Appliances.

  3. Go to the Settings tab and select or deselect Allow Log & Event Manager to detect threats based on lists of known malicious IP addresses.
    Enable Threat Feeds

  4. To verify that your Threat Feed is updating every morning, you can run the following nDepth search and look for this recurring event that comes in every morning at 3:14 AM:
    InternalInfo.EventInfo = *threat*

 

 

 

 

 

Last modified

Tags

Classifications

Public
/*]]>*/