Start a conversation

Configuring Event Source Operational Time

Overview

GFI EventsManager includes an Operational Time option through which you specify the normal working hours of your event source groups. This is required so that GFI EventsManager can keep track of the events that occur both during and outside working hours.

Use the operational time information for forensic analysis to:

  • Identify unauthorized user access
  • Identify illicit transactions carried outside normal working hours
  • Other potential security breaches that might be taking place on your network

Operational Time is configurable on a computer group basis. This is achieved by marking the normal working hours on a graphical operational time scale which is divided into one-hour segments.

Process

To configure event source properties:

  1. Navigate to Configuration tab > Event Sources > Group Type.
  2. Select Event Sources Groups.
  3. To configure settings of a:
    • Computer group:
      1. Right-click on the computer group to configure.
      2. Select Properties
    • Single event source:
      1. Right-click on the source to configure.
      2. Select Properties.
  4. From the Operational Time tab, mark the time intervals of your normal working hours.
    Note: Cells marked blue represent your normal working hours.

    Screen_Shot_2019-06-27_at_2.45.10_PM.png

  5. Click Apply and OK.
Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. Priyanka Bhotika

  2. Posted

Comments