STRM Users Guide
144
U
SING
THE
E
VENT
V
IEWER
Source IP
Specifies the source IP address associated with this event. If
there are multiple IP addresses associated with this event, this
field indicates Multiple and the number.
Destination IP
Specifies the destination IP address associated with this event. If
there are multiple IP addresses associated with this event, this
field indicates Multiple and the number.
Destination Port
Specifies the destination ports associated with this event. If there
are multiple ports associated with this event, this field indicates
Multiple and the number.
Device
Specifies the device that sent the event to STRM. If there are
multiple devices associated with this event, this field indicates
Multiple and the number.
Category
Specifies the low-level category of this event. If there are multiple
categories associated with this event, this field indicates Multiple
and the number.
For more information on categories, see the
Event Category
Correlation Reference Guide
.
Protocol
Specifies the protocol ID associated with this event.
Username
Specifies the username associated with this event, if available.
Max Magnitude
Specifies the maximums calculated magnitude for all
summarized events. Variables used to calculate magnitude
include credibility, relevance, and severity.
Count
Specifies the total number of bundled events that constitute this
normalized event. Events are bundled when many of the same
type of event for the same source and destination IP address are
seen within a short period of time.
Table 6-8
Event Name Parameters (continued)
Parameter
Description
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......