STRM Users Guide
138
U
SING
THE
E
VENT
V
IEWER
Pre NAT Source
Port
For a firewall or another device capable of NAT, this parameter
indicates the source port before the NAT values were applied.
Pre NAT
Destination IP
For a firewall or another device capable of NAT, this parameter
indicates the destination IP address before the NAT values were
applied.
Pre NAT
Destination Port
For a firewall or another device capable of NAT, this parameter
indicates the destination port before the NAT values were
applied.
Post NAT Source
IP
For a firewall or another device capable of NAT, this parameter
indicates the source IP address after the NAT values were
applied.
Post NAT Source
Port
For a firewall or another device capable of NAT, this parameter
indicates the source port after the NAT values were applied.
Post NAT
Destination IP
For a firewall or another device capable of NAT, this parameter
indicates the destination IP address after the NAT values were
applied.
Post NAT
Destination Port
For a firewall or another device capable of NAT, this parameter
indicates the destination port after the NAT values were applied.
Protocol
Specifies the protocol associated with this event.
Username
Specifies the username associated with this event, if available.
QID
Specifies the STRM identifier for this event. Each event has a
unique QID. For information on mapping a QID, see
Modifying
Event Mapping
.
Device
Specifies the device that sent the event to STRM.
Event Count
Specifies the total number of bundled events that constitute this
normalized event. Events are bundled when many of the same
type of event for the same source and destination IP address are
seen within a short period of time.
Start Time
Specifies the time of the first event, as reported to STRM by the
device.
End Time
Specifies the end time of the last event, as reported to STRM by
the device.
Device Time
Specifies the system time of the device.
Payload
Specifies payload content from the event. To view the payload in
Hex, click
Hex
. To view the payload in UTF, click
UTF
. To view in
Base64, click
Base64
.
Matched Custom
Rules
Specifies custom rules that have matched to this event. For more
information on rules, see the
STRM Administration Guide.
Annotations
Specifies the annotation or notes for this event.
Table 6-4
Event Details (continued)
Parameter
Description
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......