STRM Users Guide
Managing Network Anomalies
129
Step 4
Click
Show Flows
to view more information on the event.
The results window appears. For more information viewing flows, see
Chapter 7
Using the Flow Viewer
.
Step 5
Click
Save Report
to save the offense in a report form.
Step 6
Click
Email Report
to e-mail the offense report to a specific user.
Closing Offenses
Closing a network anomaly offense removes the information from the database.
You can close a single or all network anomaly offenses. This section includes:
•
Closing a Network Anomaly Offense
•
Closing All Offenses
Closing a Network Anomaly Offense
To close a network anomaly offense:
Step 1
Click the
Offense Manager
tab.
The Offense Manager appears.
Step 2
In the navigation menu, click
Network Anomalies
.
Step 3
Select the offense you wish to close.
Note:
To select more than one offense, press the CTRL key while you select other
events.
Step 4
Click
Close
.
Network Location
Specifies the network location that the event occurred.
Layer
Specifies the layer in which the network anomaly offense was
generated.
Event Number
Specifies the number for the event. This number increments for
each event.
Note:
If, while an event is occurring, another event occurs for
another object in the sentry, the event number does not
increment.
Response Number Specifies the number of alerts received for the sentry. This
number increments until the configured maximum is reached. If
no maximum is configured, the number continues to increment.
Response
Specifies the value that must be exceeded before the network
anomaly offense generates.
At Time of Alert
Click the graph to view information in the Network Surveillance
interface.
Now
Click the graph to view information in the Network Surveillance
interface.
Table 5-36
Details Panel (continued)
Parameter
Description
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......