STRM Users Guide
148
U
SING
THE
E
VENT
V
IEWER
c
Click
OK
.
Deleting Saved
Searches
To delete previously saved searches:
Step 1
Click the
Event Viewer
tab.
The Event Viewer window appears.
Step 2
From the Search drop-down list box, select
Edit Search
.
The filter/search window appears.
Step 3
In the Saved Searches drop-down list box, select the search you wish to delete.
Step 4
Click
Delete
.
Viewing the
Associated Offense
Some events are correlated to an offense. If a normalized or raw event has been
correlated to an offense, the event is tagged with a red icon.
To view associated offense:
Step 1
Click the
Event Viewer
tab.
The Event Viewer window appears.
Step 2
Select the normalized or raw event for which you wish to view the offense to which
the event is correlated, which is noted with a red icon.
Step 3
Click the
Offense icon.
The List of Event Categories appears.
Note:
If the offense that is associated with the selected event is not yet persisted
or purged from the database, a message appears.
Include in my
Quick
Searches
Select the check box if you wish to include this search in your Quick
Search items, which is available in the Search drop-down list box.
Share with
Everyone
Select the check box if you wish to share these search requirements
with all other STRM users.
Table 6-10
Save Search Parameters
Parameter
Description
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......