Learning Mode from logged events and Simulation Mode
Generates an action whether the event is authorized or denied (messages, profile swap, record in a journal or file, run a command, Popup alerts or Syslog)
Rules Inversion: Works in Black or White Lists
Consolidation of events from several IBM System i servers on a single Syslog console
Two client components provide the ability to centralise alerts in the Windows environment: Popup messages or via the Event Log. Event logging gives Quick-EDD/CTL the ability to interface with network security consoles.