
NOTE
To configure event notification, refer to
Section 4.2.2, “Configuring Security
Event Notification”
(page 79). After configuring security event notification,
read the reports and determine whether events require follow up. Follow up
may include the procedures outlined in
Section 4.4.1, “Receiving a Security
Event Rejection”
(page 102).
4.2.1 Severity Level Notification
You can set up Novell AppArmor to send you event messages for things that are in the
severity database and above the level that you select.These are numbered one through
ten, ten being the most severe security incident. The
severity.db
file defines the
severity level of potential security events. The severity levels are determined by the
importance of different security events, such as certain resources accessed or services
denied.
4.2.2 Configuring Security Event
Notification
Security event notification is a Novell AppArmor feature that informs you when systemic
Novell AppArmor activity occurs. When you select a notification frequency (receiving
daily notification, for example), you activate the notification. You are required to enter
an e-mail address, so you can be notified via e-mail when Novell AppArmor security
events occur.
NOTE
You must set up a mail server on your SUSE Linux that can send outgoing mail
using the SMTP protocol (for example, postfix or exim) for event notification
to work.
1
In the Enable Security Event Notification section of the AppArmor Configuration
window, click Configure.
Managing Profiled Applications
79
Summary of Contents for APPARMOR 1.2
Page 1: ...Novell AppArmor Powered by Immunix Administration Guide www novell com 1 2 09 29 2005...
Page 4: ......
Page 14: ......
Page 116: ......
Page 128: ......