background image

530-025628-01

10

STRM Log Management Release Notes

Step 5

For all systems in your deployment, use SSH to connect from the Console to 
non-Console systems and enter the following command:

service hostcontext restart

Performing an Automatic Update Does Not Deploy All Changes

When you update your system using the Auto-Update Configuration window in the 
STRM Log Management Administration Console, the changes are not enforced 
throughout your deployment. This results in updated contents do not appearing in 
the deployment. 

Workaround

: From the Administration Console Menu, select 

Configurations > 

Deploy All

 to enforce the changes. 

Event Viewer

Events Are Marked "Unknown" in Event Viewer

Events that arrive from a device that has not yet been auto-discovered are marked 
"Unknown." This is normal behavior.

Workaround

: Wait for auto-discovery to detect the device. 

Event Viewer Does not Respond to Searches

After a configuration change, the event query service process restarts and may be 
temporarily unable to process event searches. 

Workaround

: Wait between 2 and 3 minutes for the Event Viewer to finish 

restarting. Then try your search again.

Accessing Right-Click Menu in Event Viewer Causes Java Error

Using the right mouse button (right click) in the Event Viewer allows you to access 
additional menu options. If pop-ups are disabled in your web browser, a Java error 
occurs. 

Workaround

: Enable pop-ups in your web browser. 

Unable to Remove Custom Event Mapping

Once you create a custom event mapping using the event mapping tool in the 
Event Viewer, you are able to edit the mapping, however, you are unable to 
remove the event mapping or restore default settings. 

Workaround

: None. 

Reports

Size of Pie Charts in Reports is Dynamic

When creating a report that includes pie charts, the chart size depends on the area 
consumed by the legend. Pie charts with only a single item in the legend are much 
larger than pie charts with many items in the legend. 

Workaround

: Reduce the number of items you wish to display in the pie chart.

Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 - CATEGORY OFFENSE INVESTIGATION GUIDE REV 1

Страница 1: ...ager Log Management Only STRM LM provides a comprehensive log management solution for organizations that want to implement a distributed log management solution to collect archive and analyze network...

Страница 2: ...ch system in your deployment New Device Extensions Functionality You can now modify how a DSM parses logs For example you can use a device extension to detect an event that has missing or incorrect fi...

Страница 3: ...re information on Release 2008 2 refer to the on line documentation STRM Log Management Installation Guide STRM Log Management Administration Guide STRM Log Management Users Guide STRM Log Management...

Страница 4: ...a device requires STRM to forward logs through NSM Note For STRM to correctly process logs from SA and IC the logs should be sent from the devices in WELF format To enable WELF format on the device Un...

Страница 5: ...if your license key expired and you uploaded a new license key STRM Log Management did not provide the option to deploy the new license key Changing the Authentication to STRM Log Management Authentic...

Страница 6: ...nagement 2008 2 the limit of CIDR ranges you can add is approximately 200 depending on the data on your system Now Able to Apply Any IP Filter When Searching for Events Previously when you attempted t...

Страница 7: ...nt 2008 2 this directory structure is properly created Events Appear in Event Viewer and Flows in Flow Viewer After June 30 2008 The Event Correlation Engine license expires on 30 June 2008 This licen...

Страница 8: ...e configuration file and restart services Step 1 Open the configuration file on the machine that uses the custom SSL key normally the Web Server console Step 1 Add the directory path to your custom SS...

Страница 9: ...oller IC device may appear incorrectly as an Enterasys device Workaround Add the Infranet Controller device manually Infranet Controller Device Appears as Secure Access Device An auto discovered Infra...

Страница 10: ...nfiguration change the event query service process restarts and may be temporarily unable to process event searches Workaround Wait between 2 and 3 minutes for the Event Viewer to finish restarting Th...

Страница 11: ...per Networks Inc in the United States and other countries JUNOS and JUNOSe are trademarks of Juniper Networks Inc All other trademarks service marks registered trademarks or registered service marks a...

Отзывы: