STRM Users Guide
100
I
NVESTIGATING
O
FFENSES
The Attacker details toolbar provides the following functions:
Step 4
To view a list of local targets, click
Targets.
The List of Local Targets appears.
Location
Specifies the location of the attacker.
Offense(s)
Specifies the names of the offenses associated with this
attacker. To view additional information on the offense, click the
name or term that appears.
Local
Target(s)/Dest
Specifies the local target of the offense. To view additional
information on the target, click the IP address or term that
appears.
If the target is a single source, an IP address appears. You can
click the IP address to view the target details. If there are
multiple targets, the term Multiple appears. Click
Multiple
for a
table of targets to appear at the bottom of the panel.
Event Count
Specifies the total number of events associated with this
attacker.
First event seen on Specifies the date and time in which this attacker generated the
first event.
Last event seen on Specifies the date and time of the last generated event
associated with this attacker.
Table 5-10
Attacker Panel Toolbar
Icon
Function
Allows you to view the list of local targets for this attacker. See
Step 4
.
Allows you to view a list of offenses associated with this attacker. See
Step 5
.
Actions
Using the Actions drop-down list box, you can choose one of the
following actions:
•
Follow up
- Allows you to mark this attacker for further follow-up.
See
Marking an Item For Follow-Up
.
•
- Allows you to be notified through e-mail in the event this
attacker changes. See
Configuring Notification
.
•
Notes
- Allows you to add notes to the attacker. See
Adding Notes
.
•
- Allows you to print this attacker.
Table 5-9
Attacker Details Panel (continued)
Parameter
Description
Table 5-11
List of Local Targets
Parameter
Description
Flag
Specifies action taken on the target, for example, if a flag
appears, the offense is marked for follow-up. Point your mouse
over the icon to display additional information.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......