STRM Users Guide
140
U
SING
THE
E
VENT
V
IEWER
Viewing Aggregate
Normalized Events
Using the Event Viewer, you can view events aggregated (grouped) by various
options.
Start Time
Specifies the time of the first event, as reported to STRM by the
device.
Device
Specifies the device that originated the event.
Payload
Specifies the original event payload information in UTF-8 format.
Table 6-6
Raw Events Parameters (continued)
Parameter
Description
Table 6-7
Aggregate Normalized Events
Aggregate Option
Description
Event Name
Displays a summarized list of events grouped by the
normalized name of the event.
Source IP
Displays a summarized list of events grouped by the source
IP address of the event.
Destination IP
Displays a summarized list of events grouped by the
destination IP address of the event.
Source Port
Displays a summarized list of events grouped by the source
port address of the event.
Destination Port
Displays a summarized list of events grouped by the
destination port address of the event.
High Level Category
Displays a summarized list of events grouped by the
high-level category of the event.
For more information on categories, see the
Event Category
Correlation Reference Guide
.
Low Level Category
Displays a summarized list of events grouped by the
low-level category of the event.
For more information on categories, see the
Event Category
Correlation Reference Guide
.
Magnitude
Displays a summarized list of events grouped by the
magnitude for this event. The variables used to calculate
magnitude include credibility, relevance, and severity.
Credibility
Credibility indicates the integrity of an event as determined
by the credibility rating from source devices. Credibility
increases as the multiple sources results grouped by the
credibility of the event. This aggregate option displays a
summarized list of events grouped by the credibility of the
event.
Severity
Severity indicates the amount of threat an attacker poses in
relation to how prepared the target is for the attack. This
value is mapped to an event category that is correlated to
the offense. This aggregate option displays a summarized
list of events grouped by the severity of the event.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......