
Traffic summary and security events
Security event summaries
FortiAnalyzer Version 3.0 MR3 Administration Guide
05-30003-0082-20060925
113
Security event summaries
Security event summaries are reports that provide a snapshot of unwanted traffic
that is attempting to breach the firewall. The FortiAnalyzer unit has four default
event reports that are updated daily:
• Virus
• Intrusion
• Suspicious
• Administrative.
Adding a security event report
The FortiAnalyzer unit includes default security event reports for virus, intrusion
and suspicious activity events. You can add customized event correlation reports
to configure when the FortiAnalyzer unit generates the reports and what device
logs the FortiAnalyzer uses in compiling the report.
To configure an event correlation
1
Go to
Network Summary
>
Config
>
Event Correlation
.
2
Select Create new.
3
Complete the following options and select OK:
Viewing the security event reports
To view the event correlations report details, go to
Network Summary
>
Config
>
Event Correlation
.
Name
Enter a name for the event correlation report.
Devices/Groups
Select a device or group of devices that the FortiAnalyzer unit runs
the report against. The FortiAnalyzer unit uses the logs for the
selected device(s).
Run Engine
Select to generate either a daily report or a weekly report of event
activity.
Time
Select the time of day when the FortiAnalyzer unit runs the report.
Select Daily and select the time of the day to run the report each
day.
Select Weekly, and select the days of the week when the
FortiAnalyzer unit runs the report each week.
Engine Type
Select the type of event correlation report to run.
Ignore hosts that
have less than
n
incidents
Select to set a threshold for the number of incidents occurring
from an individual source, and set the threshold value. For
example, if a single source tries to send multiple viruses more
than the set threshold, then the FortiAnalyzer unit considers it one
virus event.
Ignore hosts whose
traffic is less than
n
MB
This option appears only when configuring a Suspicious report.
Select to set a threshold for the minimum acceptable amount of
traffic occurring from an individual source, and set the threshold
value. For example, if a single source tries to send multiple
viruses or attacks more than the set threshold for content traffic,
then the FortiAnalyzer unit considers it one virus event.
Содержание FortiAnalyzer-100A
Страница 1: ...www fortinet com FortiAnalyzer Version 3 0 MR3 A D M I N I S T R A T I O N G U I D E...
Страница 10: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 10 05 30003 0082 20060925 Contents...
Страница 76: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 76 05 30003 0082 20060925 Blocked Devices Devices...
Страница 88: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 88 05 30003 0082 20060925 Log rolling Logs...
Страница 94: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 94 05 30003 0082 20060925 Log rolling Content archive...
Страница 138: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 138 05 30003 0082 20060925 Output Alerts...
Страница 150: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 150 05 30003 0082 20060925 Log rolling Network Analyzer...
Страница 156: ...FortiAnalyzer Version 3 0 MR3 Administration Guide 156 05 30003 0082 20060925 Reports Vulnerability scan...
Страница 161: ...www fortinet com...
Страница 162: ...www fortinet com...