Hi everyone,
I’m fairly new to using ArcSight and wanted to ask—how often do you recommend updating or reviewing threat detection rules and correlation logic? I want to make sure our system stays current without overloading it with constant changes. Any general advice or best practices would be appreciated!
Thanks!