Idea ID 2774980
Here is advice for feature request to include additional information for the ArcSight Internal Event relating to the updating of resources, where Device Event Class ID = resource:101. The type of change to the resource be noted within the event, such as “Filter”, “Aggregation”, “Local Variables”, etc. In order to enable they to develop rules and reports around said event. It will be good to see this for Filters and Rules, but also Reports, Queries, Active Lists and Users if possible. Ideally to add to an existing event processed by ESM to understand what part of the resource has changed, as opposed to retaining a version history between changes, so that we are able to identify which element of a resource has changed.
In terms of resources, we would be looking for this change on the following resource types: filters, rules, reports, queries, active lists and users.
When updating a resource such as a rule, the clarity of what element was changed is not recorded just that the rule was updated in some capacity
Comparison with another system which is not always ideal.
No idea what part of a resource was changed e.g. a rule changed but not sure if it was the aggregation, the filter conditions the output etc.
Also include what element of the rule or any resource was changed so there is a greater knowledge what a person did with the resource.
Before was created NGS-28716
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.