Configuring DSMs
236
N
AME
V
ALUE
P
AIR
EventName
Type the event name that you want to use to identity the
event in the Events interface when using the Event
Mapping functionality. For more information on mapping
events, see the
SIEM Users Guide.
This is a required parameter.
EventCategory
Type the event category you want to use to identify the
event in the Events interface. If this value is not included in
the log message, the value
NameValuePair
value is
used.
SourceIp
Type the source IP address for the message.
SourcePort
Type the source port for the message.
SourceIpPreNAT
Type the source IP address for the message before
Network Address Translation (NAT) occurred.
SourceIpPostNAT
Type the source IP address for the message after NAT
occurs.
SourceMAC
Type the source MAC address for the message.
SourcePortPreNAT
Type the source port for the message before NAT occurs.
SourcePortPostNAT
Type the source port for the message after NAT occurs.
DestinationIp
Type the destination IP address for the message.
DestinationPort
Type the destination port for the message.
DestinationIpPreNAT
Type the destination IP address for the message before
NAT occurs.
DestinationIpPostNAT
Type the IP address for the message after NAT occurs.
DestinationPortPreNAT
Type the destination port for the message before NAT
occurs.
DestinationPortPostNAT Type the destination port for the message after NAT
occurs.
DestinationMAC
Type the destination MAC address for the message.
DeviceTime
Type the time that the event was sent, according to the
device. The format is: YY/MM/DD hh:mm:ss. If no specific
time is provided, the syslog header or DeviceType
parameter is applied.
UserName
Type the user name associated with the event.
HostName
Type the host name associated with the event. Typically,
this parameter is only associated with identity events.
GroupName
Type the group name associated with the event. Typically,
this parameter is only associated with identity events.
NetBIOSName
Type the NetBIOS name associated with the event.
Typically, this parameter is only associated with identity
events.
Table 44-1
NVP Log Format Tags (continued)
Tag
Description
Содержание Security Information and Event Manager
Страница 1: ...Enterasys Security Information and Event Manager SIEM Configuring DSMs Release 7 7 0 P N 9034592 05...
Страница 2: ......
Страница 8: ......
Страница 20: ......
Страница 22: ......
Страница 24: ......
Страница 26: ......
Страница 32: ......
Страница 34: ......
Страница 36: ......
Страница 38: ......
Страница 44: ......
Страница 58: ......
Страница 90: ......
Страница 92: ......
Страница 94: ......
Страница 114: ......
Страница 116: ......
Страница 122: ......
Страница 124: ......
Страница 126: ...Configuring DSMs 110 FIREEYE...
Страница 128: ......
Страница 130: ......
Страница 132: ......
Страница 136: ......
Страница 140: ......
Страница 144: ......
Страница 172: ......
Страница 176: ...Configuring DSMs 160 ISC BIND...
Страница 180: ......
Страница 182: ......
Страница 184: ......
Страница 204: ......
Страница 224: ......
Страница 246: ......
Страница 250: ......
Страница 256: ......
Страница 260: ......
Страница 276: ......
Страница 282: ......
Страница 284: ......
Страница 306: ......
Страница 308: ......
Страница 318: ......
Страница 322: ......
Страница 324: ......
Страница 346: ......
Страница 356: ......
Страница 366: ......
Страница 384: ......
Страница 392: ......
Страница 394: ......
Страница 396: ......
Страница 398: ......
Страница 404: ......
Страница 426: ......