STRM Users Guide
Viewing Events
141
Relevance
Relevance indicates the significance of an event. This option
displays a summarized list of events grouped by the
relevance of the event.
Username
Displays a summarized list of events grouped by the
username associated with the events.
Device
Displays a summarized list of events grouped by the devices
that sent the event to STRM.
Device Type
Device Type indicates the type of device that originated the
event. This aggregate option displays a summarized list of
events grouped by device type.
Device Group
Displays a summarized list of events grouped by device
group.
Network
Displays a summarized list of events grouped by the network
associated with the event.
Src IP/ Dst IP / Dst
Port/ User
Displays a summarized list of events grouped by the source
IP address, destination IP address, destination port, and the
user.
Src IP/ Dst IP / Dst
Port/ Event Name
Displays a summarized list of events grouped by the source
IP address, destination IP address, destination port, and the
name of the event.
Src IP/ Event Name/
User
Displays a summarized list of events grouped by the source
IP address, event name, and user.
Src IP/ Dst IP/ Event
Name/ User
Displays a summarized list of events grouped by the source
IP address, destination IP address, event name, and user.
Src IP/ Dst IP/ User
Displays a summarized list of events grouped by the source
IP address, destination IP address , and the username
associated with the event.
Src IP / Dst IP
Displays a summarized list of events grouped by traffic from
the source IP address to destination IP address.
Dst IP/ Port
Displays a summarized list of events grouped by destination
IP address and port.
Event Name/ Device
Displays a summarized list of events grouped by the event
name and the device that sent the event to STRM.
Device/ High Level Cat Displays a summarized list of events grouped by the device
that sent the event to STRM and the high-level category.
For more information on categories, see the
Event Category
Correlation Reference Guide
.
Device/ High Level
Cat./ Low Level Cat.
Displays a summarized list of events grouped by the device
that sent the event to STRM and the high and low-level
categories.
Matched Custom Rule Displays a summarized list of events grouped by the
associated custom rule.
Table 6-7
Aggregate Normalized Events (continued)
Aggregate Option
Description
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......