Who rated this post

cancel
Showing results for 
Search instead for 
Did you mean: 
Henrik_Noerr1
Advisor

Hey,

All our firewall logs are sent to an elastic instance with the log exporter. From here we have set up alerts on various logs. So when IOC stops working the firewall logs it, and we sent a webhook from elastic to our ITSM with relevant info.

 

Furthermore we have a query every X minute from a tooling server, that queries an item agreed to be in the feed. The query should be stopped. If it is not, we sent an alert to our ITSM system.

 

/Henrik

(1)
Who rated this post