11-21-2023 12:51 AM
We have observed more count for Unix Critical File Accessed Detected alert from the user “root” on the Host XYZ-FMC-SECONDARY. And also we observed multiple File names which is containing /etc, due to that alert is triggering.
Can anyone help me how to resolve this.
11-21-2023 05:32 AM
What system is showing you this alert? Can you provide a sanitized screen shot?
11-22-2023 12:59 AM
11-22-2023 05:02 AM
Attaching a random spreadsheet does not answer the question "What system is showing you this alert?"
11-22-2023 07:15 AM
Its ALsec threat management tool that collects fmc logs
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide