Translating Qradar rules to SPL and stocked with setting thresholds
300 events are seen with the same Source IP and different Destination IP in 1 hour
no idea which parameters to use ? any hints ?
↧