Team: Huntress Managed Security Information and Event Management (SIEM)
Product: Managed SIEM
Environment: Huntress Platform
Summary: Learn how to enable, configure, and manage non-reporting log source escalations in Huntress Managed SIEM.
In This Article
Overview
Enable Non-Reporting Log Source Escalations
Escalation Trigger Conditions
Mute or Stop Monitoring Log Sources
Auto-Close Escalations
Overview
Non-reporting log source escalations notify Account admins when a log source stops sending data to Huntress Managed Security Information and Event Management (SIEM). This guide explains how to enable these escalations and manage non-reporting sources.
Enable Non-Reporting Log Source Escalations
Account admins can enable non-reporting log source escalations directly in the Huntress Platform.
Log in to Huntress and go to SIEM > Source Management.
Select the Settings tab.
Toggle Escalations to On.
From the duration dropdown list, select 1, 4, or 8 hours to set how long a log source must be offline before triggering an escalation.
Save your changes.
Escalation Trigger Conditions
Huntress generates an escalation when a log source meets both of the following criteria:
Consistent Reporting History: The log source reported consistently (at least once per hour) for 7 consecutive days before going offline. If an offline log source triggers an escalation and later resumes reporting, it must remain active for 7 consecutive days before escalations can be triggered again.
Configured Offline Duration: The log source remains offline for the duration configured in your Escalations settings (1, 4, or 8 hours).
Mute or Stop Monitoring Log Sources
When responding to a non-reporting log source escalation, you can select one of two management options:
Mute: Applies only to the active escalation. If the log source goes offline again in the future and meets the escalation criteria, Huntress creates a new escalation.
Stop monitoring: Removes the log source from active monitoring. Huntress will not generate future escalations for this source.
Auto-Close Escalations
If a log source that triggered an escalation starts reporting again, Huntress automatically closes the escalation. You do not need to take any additional action.