STRM Users Guide
Modifying Event Mapping
149
For information on managing offenses, see
Chapter 5
Investigating Offenses
.
Modifying Event
Mapping
STRM automatically maps an event of a Device Support Module (DSM), also
known as a sensor device, for normalization purposes. Using the event mapping
tool, you can associate or map a normalized or raw event to a high-level and
low-level category (or QID). This allows STRM to map unknown device events to
known STRM events so that they can be categorized and correlated appropriately.
STRM may receive events from DSMs that the system is unable to categorize.
STRM categorizes these types of events as unknown. These events may occur for
several reasons including:
•
User-defined Events
- Some DSMs, such as SNORT, allow you to create
user-defined events.
•
New Events or Older Events
- Third party devices may update their software
with maintenance releases to support new events that STRM may not support.
To modify event mapping:
Step 1
Click the
Event Viewer
tab.
The Event Viewer window appears.
Step 2
For any normalized event, double-click the event you wish to map.
For more information on viewing normalized events, see
Viewing Normalized
Events
. For information on viewing raw events, see
Viewing Raw Events
.
Step 3
Click
Map Event.
The Device Event window appears.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......