WANGUARD 5.2 User Manual & Administrator's Guide
Conditional & Dynamic Parameters
#
CONDITIONAL PARAMETER
TYPE
DYNAMIC PARAMETER
DESCRIPTION
GENERAL PARAMETERS
1
IP Address
String
{ip}
The IP or Subnet involved in the anomaly.
String
{ip_dns}
The reverse DNS of the IP involved in the
anomaly. It's {ip} if the lookup is not
successful.
2
CIDR
Number
{cidr}
The CIDR (prefx mask) of the IP or
Subnet involved in the anomaly.
3
Prefx
String
{prefix}
The IP/CIDR involved in the anomaly.
4
IP Group
String
{ip_group}
The IP Group of the IP or Subnet involved
in the anomaly.
5
Sensor Name
String
{sensor}
The Sensor's name.
6
Sensor Group
String
{sensor_group}
The Sensor's Interface Group.
7
Sensor IP
String
{sensor_ip}
The IP of the server running the Sensor.
8
Sensor Type [snif,fow,virtual]
String
{sensor_type}
It's “snif” for the Snifng Sensor, “fow”
for the Flow Sensor, or “virtual” for the
Virtual Sensor.
9
Sensor ID
Number
{sensor_id}
The unique ID of the Sensor.
10
Flow Exporter IP
String
{router_ip}
The Flow exporter's IP. Empty when using
the Snifng Sensor.
11
IP Zone Name
String
{ipzone}
The IP Zone used by the Sensor.
12
Response Name
String
{response}
The Response used for the anomaly.
13
Template Name
String
{template}
The Template that defned the anomaly's
triggering rule, if any.
14
Expiraton Delay (seconds)
String
{expiration}
The number of seconds between the last
tme the anomaly is detected and the tme
the anomaly is expired.
15
Captured Packets
Number
{captured_pkts}
The number of captured packets during
the Response, if any.
16
BGP Log Size (bytes)
Number
{bgplog_bytes}
The size of the BGP announcements logs.
17
Unique Dynamic Parameters
String
{exclusive}
The Unique Dynamic Parameters contain
Dynamic Parameters that must be unique
for the validaton of an Acton.
ANOMALY PARAMETERS
1
Anomaly Descripton
String
{anomaly}
A descripton of the anomaly.
- 35 -
Summary of Contents for Wanguard 5.2
Page 1: ......