134 Responding
Managing response rules
Editing response rules
The Network Security console provides a way to modify response rules easily.
To view Response Policy Configuration
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
In
Response Rules
, select a response rule. The background of the selected
response rule turns purple.
3
Click one of the following to edit:
■
Setting event targets
■
Setting event types
■
Setting severity levels
■
Setting confidence levels
■
Setting event sources
■
Setting response actions
■
Setting next actions
4
Click
OK
to save and exit.
Searching event types
All users can view a more manageable subset of the entire event list by using any
or all of the search criteria to shorten the list of event types in the Search Event
List.
To select event types
1
In the Network Security console, click
Configuration
>
Response Rules
>
Event Type
.
2
To see the Event Lists, double-click
Event Types
.
3
In
Search Events
, provide some or all of the following search criteria:
■
Click
Title
to identify the search.
■
Click
Protocol
to search for specific protocols.
■
Click
Category
to search for specific categories.
■
Click
Severity
to indicate the severity level.
■
Click
Confidence
to indicate the confidence level.
■
Click
Intent
to indicate the intent.
4
After selecting search criteria, click
Search Events
.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...