Configuring Routing Rules to Use the JSA Data Store
A new offering, JSA Data Store, normalizes and stores both security and operational log data for future analysis and review. The offering supports the storage of an unlimited number of logs without counting against your organization’s Events Per Second JSA license, and enables your organization to build custom apps and reports based on this stored data to gain deeper insights into your environments.
Using the Log Only (Exclude Analytics) option requires entitlement for JSA Data Store, but is not currently enforced. In the future, when entitlement is enforced, access to the collected event data will be restricted to properly licensed systems. When the license is applied and the Log Only (Exclude Analytics) option is selected, events that match the routing rule will be stored to disk and will be available to view and for searches. The events bypass the custom rule engine and no real-time correlation or analytics occur. The events can't contribute to offenses and are ignored when historical correlation runs.
The following apps also ignore Log Only events:
-
JSA User Behavior Analytics
-
JSA Advisor with Watson