SIEM Stream Creation/Modification In AIS Managed SIEM
Key steps:
- Find the AIS Managed SIEM Input you wish to use for the new Stream.
- Click “Show Received Messages” next to the desired Input. Copy the Search Query near the top of the page.
- Click “Create Stream”.
- Add title and Description.
- Click checkbox “Remove matches from All Messages” stream.
- Click “Save”.
- Find the newly created Stream and click “Manage Rules” next to it.
- Click “Add Stream Rule”.
- In the Field textbox, type gl2_source_input Value textbox.
- Use the second part of the Search Query from Step 2. Note: Do not include the colon.
- Type the Input Name as the description.
- Click “Save”.
- Click the radio button on the left side “A message must match at least one of the following rules”.
- Click “I’m done!”
- Find the newly created Stream and click “Start Stream”.
- Click the Stream name to verify that messages are now appearing in the Stream.
Last modified
April 15, 2021