Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature Request: Track by None #77

Open
OGSteve opened this issue Oct 4, 2023 · 0 comments
Open

Feature Request: Track by None #77

OGSteve opened this issue Oct 4, 2023 · 0 comments

Comments

@OGSteve
Copy link

OGSteve commented Oct 4, 2023

Per conversation with Da Beave, we should have a "track by none" option so that a single rule could be set to fire an alert after X amount of instances, regardless of the log source. For example:

In a ransomware event we might see multiple policy changes across an environment and so we would want to track by the event itself across an entire network rather than a single Domain Controller.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant