STRM Users Guide
6
A
BOUT
STRM
Flow Viewer
The Flow Viewer tab allows you to monitor and investigate flow data in real-time or
perform advanced searches. A flow is a communication session between two
hosts. Viewing flow information allows you to determine how the traffic is
communicated, what was communicated (if the content capture option is enabled),
and includes such details as when, who, how much, protocols, ASN values, IfIndex
values, or priorities.
Note:
For more information, see
Chapter 7
Using the Flow Viewer
.
Assets
STRM automatically discovers assets (servers and hosts) operating on your
network, based on passive QFlow data as well as vulnerability data allowing STRM
to build an asset profile. Asset profiles display what services are running on each
asset. This profile data is used for correlation purposes to help reduce false
positives, for example, if an attack occurs trying to exploit a specific service
running on a specific asset, STRM can determine if the asset is vulnerable to this
attack by correlating the attack to the asset profile. Using the Assets tab, you can
view all the learned assets or search for specific assets to view there profiles.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......