Get a notification when fields in parsed events match criteria you specify.
Some activity appears suspicious because the event's data matches data in a list or another event (such as a logon attempt by a user in the former_employee watchlist).
Note
The values used with the Regex, Does not match regex, Contains, and Does not contain operators can be case sensitive or case insensitive depending on the rules or Default correlation manager settings. The watchlists listed under a filter field may not be case insensitive. All values within the watchlists are evaluated as case-sensitive.
From the Trellix ESM dashboard, click
and select More Settings.On the system navigation tree, select Trellix ESM and click
.Click → .
Enter the Name and select the Assignee.
In the Condition tab, select Field Match for Type field.
Set up the conditions for the alarm.
Drag and drop the AND or OR to set up the logic for the alarm's condition.
Drag and drop the Match Component icon onto the logic element, then complete the Add Filter Field page.
In the Maximum Condition Trigger Frequency field, select the amount of time to allow between each condition to prevent a flood of notifications.
Note
Each trigger only contains the first source event that matches the trigger condition, not the events that occurred in the trigger frequency period. New events that match the trigger condition do not cause the alarm to trigger again until after the maximum trigger frequency period.
Note
If you set the interval to zero, every event that matches a condition triggers an alarm. For high frequency alarms, a zero interval can produce many alarms.
Click Next and select the devices to be monitored for this alarm. This alarm type supports Receivers, local Receiver-Enterprise Log Managers (ELMs), Receiver/ELM combos, ACEs, and Application Data Monitors (ADMs).
Click the Actions and Escalation tabs to define the settings, then click Finish.
If the alarm fails to write out to the device, an out-of-sync flag appears next to the device in the system navigation tree. Click the flag, then click Sync Alarms.
The alarm writes out to the device.