Zero Networks asset is no longer monitored by cloud connector
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Detects assets that are no longer being monitored by cloud connector.
Strategy
Monitor audit logs and notify when an asset is no longer monitored by cloud connector. This may indicate that an unauthorized user disabled monitoring to avoid detection.
Triage and Response
- Review audit logs to identify any events or actions that caused the asset to stop being monitored by the cloud connector.
- Check the health and status of the cloud connector to ensure it is functioning correctly and maintaining connectivity with the affected asset.
- Review user role
{{@user_role}}
and enforcement source {{@enforcement_source}}
to identify the user role or system triggering the event. - Evaluate if the unmonitored asset poses any immediate security risks (such as unauthorized access).
- Implement immediate measures based on the audit log findings to address any security concerns.