Alert Correlation Rules and Grouping Mechanism to Reduce Noise

  Рет қаралды 6,327

Ashutosh Munot

Ashutosh Munot

Күн бұрын

Пікірлер: 30
@NghiNguyen-ug8ur
@NghiNguyen-ug8ur Жыл бұрын
Your content is much much better than the nowlearning on-demand course! Keep doing this, Thanks!!
@AshutoshMunot
@AshutoshMunot Жыл бұрын
Glad you think so!
@rupalirasal6846
@rupalirasal6846 4 ай бұрын
Hello, do you have any other documentation on alert management?
@dtonomy8635
@dtonomy8635 3 жыл бұрын
This is very useful! Same amount of noises do exist in security detections alerts. Grouping alerts not only reduce noise but also provide valuable context for security analysts to quickly identify true positives and false positives. In our product we have designed a module called pattern discovery. It automatically pulls all detections using the detections API so our Pattern Discovery Engine can automatically cross-correlate all the detections into a much smaller number of Cases. Since cross-correlating could be time consuming when done manually, we've automated that step in our product… Anyways, Good demo, Ashutosh!
@AshutoshMunot
@AshutoshMunot 3 жыл бұрын
Thanks for your inputs @DTonomy
@amysrisai
@amysrisai 3 жыл бұрын
Thank you for explaining the Alert correlation & grouping using Rule and OOTB methods so well. I would also be interested in how Learned Patterns are created and managed. If you could add a video on this, that would be greatly appreciated.
@AshutoshMunot
@AshutoshMunot 3 жыл бұрын
Great suggestion!
@ravigaur583
@ravigaur583 3 ай бұрын
Best explanation, Thanks
@oswaldoperalta
@oswaldoperalta 2 жыл бұрын
Awesome tutorial man. Thank you!
@AshutoshMunot
@AshutoshMunot 2 жыл бұрын
Glad it was helpful!
@Avdacademy
@Avdacademy 2 жыл бұрын
Hello Ashutosh l, I created four events with the same source with the same CI and different message keys. Even they are grouping automatically. Could you confirm me on this . How the automatic rule works.
@aakuSBhan
@aakuSBhan 4 жыл бұрын
nice video..Very Helpfull.
@AshutoshMunot
@AshutoshMunot 4 жыл бұрын
Many many thanks
@sharathkumar7938
@sharathkumar7938 Жыл бұрын
Can we disable auto alert grouping for some type of alerts???
@vaasant10
@vaasant10 3 жыл бұрын
Nice Video ..Bro
@AshutoshMunot
@AshutoshMunot 3 жыл бұрын
Thanks
@TaleleMilind
@TaleleMilind 4 жыл бұрын
Thank you Ashutosh for this nice video. I want to replicate similar incident/ parent child incident mechanism in program. please can you help, what rule need to be consider while doing ML
@AshutoshMunot
@AshutoshMunot 4 жыл бұрын
Sure. When you say parent child incident means you want to create incident for all secondary alerts as well and make them child of primary alert incident?
@TaleleMilind
@TaleleMilind 4 жыл бұрын
Yes, Primary incident( lets say Diskspace issue) and child are rest of jobs failed due to primary issue. Can you guide on some ML algorithms that can be use outside serviceNow.
@AshutoshMunot
@AshutoshMunot 4 жыл бұрын
@@TaleleMilind You can make use of patterns here. You can create rule based correlation as well. How you know they are child? Based on CI relationship? If yes then they are automatically handled by ServiceNow if you have proper relationship in cmdb.
@TaleleMilind
@TaleleMilind 4 жыл бұрын
@@AshutoshMunot Not on CI relation. I need to create some relation. Does any ML will tell me that they are related?
@AshutoshMunot
@AshutoshMunot 4 жыл бұрын
@@TaleleMilind we can have Manual correlation and that correlation will be recorded and next time automatically ServiceNow will use it when new alert is created
@SudiptaGoswami2
@SudiptaGoswami2 3 жыл бұрын
👍👍👍
@evaa_121
@evaa_121 4 жыл бұрын
if we do manual grouping, you mentioned that next time alert aggregation runs, then servicenow will automatically does the grouping next time right. In that case, will it show the grouping as 'Automated'?
@AshutoshMunot
@AshutoshMunot 4 жыл бұрын
Yes
@evaa_121
@evaa_121 4 жыл бұрын
@@AshutoshMunot thanks for replying. is there a way to revert that. (in case when the person wrongly does the manual grouping)
@jacoba8851
@jacoba8851 3 жыл бұрын
Hello does this require to purchase any separate module from service now?
@AshutoshMunot
@AshutoshMunot 3 жыл бұрын
EVENT MANAGEMENT MODULE
Event Management : Event Rules
16:43
Ashutosh Munot
Рет қаралды 6 М.
Get started with ITOM Visibility
58:47
ServiceNow Community
Рет қаралды 865
Арыстанның айқасы, Тәуіржанның шайқасы!
25:51
QosLike / ҚосЛайк / Косылайық
Рет қаралды 673 М.
1% vs 100% #beatbox #tiktok
01:10
BeatboxJCOP
Рет қаралды 24 МЛН
How to use correlation rules for effective threat detection
40:26
ManageEngine IAM and SIEM
Рет қаралды 2,7 М.
"I Didn't Know ServiceNow Did That!" - Tag based alert correlation
27:46
ServiceNow Community
Рет қаралды 3,3 М.
7 Steps to Write Standard Operating Procedures that ACTUALLY Work
15:21
Layla at ProcessDriven
Рет қаралды 77 М.
SIEM Correlation Rules for Beginners
15:08
Prabh Nair
Рет қаралды 10 М.
Getting Started with ServiceNow Event Management
57:13
Kloves Inc.
Рет қаралды 18 М.
ITOM Talks Session #3 - Health Log Analytics
48:54
ServiceNow Community
Рет қаралды 2,5 М.
Alert Management Rule : Part One Overview
7:30
Ashutosh Munot
Рет қаралды 4,4 М.
How to: Get Started with ITOM Event Management
46:21
ServiceNow Community
Рет қаралды 6 М.
How To - Event Management
54:06
ServiceNow Community
Рет қаралды 8 М.