STRM Series II Hardware Installation Guide
22
P
REPARING
YOUR
S
YSTEM
FOR
STRM S
OFTWARE
I
NSTALATION
discovered by STRM appear in the Sensor Devices window within the STRM
Administration Console. Once auto discovery is completed, you should disable the
Auto Detection Enabled option in the Event Collector configuration. For more
information, see the
STRM Administration Guide
.
Non-syslog-based information sources must be added to your deployment manually.
For more information, see the
Managing Sensor Devices Guide
. For each device you
wish to add to your deployment, record the device in
Table 15
.
In this table:
•
Link Speed & Type indicates the maximum network link (in Kbps) for firewall,
router, and VPN devices. Record the primary application of the host system -
for example, e-mail, anti-virus, domain controller, or workstation.
•
Msg Level indicates the message level you wish to log - for example, critical,
informational, or debug.
•
No. of Users indicates the maximum number of hosts and users using or being
served by this device.
•
Network Location indicates whether this device is located on the Internet
demilitarized zone (DMZ), Intranet, or Extranet DMZ.
•
Geographic Location indicates whether the devices are located on the same
LAN as STRM or sending logs over the WAN identified in the Link Speed &
Type column.
Credibility indicates the integrity of an event or offense as determined by the credibility
rating from source devices. Credibility increases as multiple sources report the same
event.
Identifying Network
Assets
STRM can learn about your network and server infrastructure based on flow data.
The Server Discovery function uses the STRM Asset Profile database to discover
many types of servers.
Table 15 Devices
Device
Type
QTY
Product
Name/
Version
Link
Speed
& Type
Msg
Level
Avg
Log
Rate
(Event /
Sec)
No. of
Users
Network
Location
Geograp
hic
Location
Credibi
lity (0
to 10)