cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
498
Views
0
Helpful
2
Replies

Can you read a dropped event?

scootertgm
Level 1
Level 1

I had a mis-configured drop rule that logged to the DB.

Is it possible to go back and review the event in the DB to get the info from the attack?

1 Accepted Solution

Accepted Solutions

hoffa2000
Level 3
Level 3

With the risk of telling you something you already know...events "logged to DB" are excluded from the incident process but processed when creating reports, so one solution in this case would be to set up a raw data report to see what exactly was logged.

/Fredrik

View solution in original post

2 Replies 2

hoffa2000
Level 3
Level 3

With the risk of telling you something you already know...events "logged to DB" are excluded from the incident process but processed when creating reports, so one solution in this case would be to set up a raw data report to see what exactly was logged.

/Fredrik

You and I had similar ideas. I pulled the raw logs and it was able to answer my questions.

Sorry it was late in the day or I would have replied earlier.