STRM Users Guide
6
U
SING
THE
E
VENT
V
IEWER
An event is an action that occurs on a network or a host. The Event Viewer allows
you to monitor and investigate events in real-time or perform advanced searches.
The Event Viewer indicates which events are being correlated to offenses and
which are not.
You can also use the Event Viewer to:
•
Associate or map an unknown event to a high-level and low-level category (or
QID).
•
Tune false positive events from generating offenses.
•
Search events.
•
View event information aggregated by various options.
•
Export events in XML or CSV format.
You must have permission to view the Event Viewer interface. For more
information on assigning roles, see the
STRM Administration Guide
.
This chapter provides information on using the Event Viewer including:
•
Using the Event Viewer Interface
•
Viewing Events
•
Searching Events
•
Viewing the Associated Offense
•
Modifying Event Mapping
•
Tuning False Positives
•
Exporting Events
Note:
When STRM normalizes events, the system normalizes names as well.
Therefore, the name that appears in the Event Viewer may not match the name
that appears in the event.
Summary of Contents for SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Page 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Page 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Page 138: ......
Page 226: ......