STRM Users Guide
Tuning False Positives
151
Tuning False
Positives
You can use the Event Viewer to tune out False Positive events from created
offenses in STRM by using the False Positive Tuning function. You must have
appropriate permissions for creating customized rules to tune false positives. For
more information on roles, see the
STRM Administration Guide
. You can tune false
positive events from any summary or details panel.
To tune a false positive event:
Step 1
Click the
Event Viewer
tab.
The Event Viewer window appears.
Step 2
Select the event you wish to tune.
Step 3
Click
False Positive.
The False Positive window appears with information derived from the selected
event.
Step 4
Select one of the following Event Property options:
•
Events with a specific QID of <Event>
•
Any Events with a low level category
•
Any Events with a high level category
•
Any Events
Step 5
Select one of the Traffic Direction options:
•
<Source IP Address> to <Destination IP Address>
•
<Source IP Address> to Any Destination
•
Any Source to <Destination IP Address>
•
Any Source to any Destination
Summary of Contents for SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Page 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Page 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Page 138: ......
Page 226: ......