Forum Discussion

Jan_F1801's avatar
Jan_F1801
Copper Contributor
Oct 26, 2020

Time delay for messages in Sentinel

We have set up the connector to MDATP.
Messages that are displayed there take a long time until the info is displayed in Sentinel.
How do we get the information displayed in Sentinel in real time?
Such a long delay is not very nice from a security point of view.

 

3 Replies

  • Jan_F1801's avatar
    Jan_F1801
    Copper Contributor
    Kann denn wirklich niemand sagen warum die Anzeige so sehr verzögert im Sentinel ankommt?
    • mclaes's avatar
      mclaes
      Brass Contributor

      Jan_F1801 I share your concern. If the delays are too large, we're better off using email alerts straight from the log source (WDATP, MCAS, ASC ...). 
      Don't know if 'the silent majority' feels this is a problem too or if we are the only two 🙂

      • Thijs Lecomte's avatar
        Thijs Lecomte
        Bronze Contributor
        I have the same delay... Unfortunately this is nothing you can do

Resources