STRM Users Guide
4
M
ANAGING
S
ENTRIES
Sentries provide an alerting function for your network. A sentry can monitor any
number of views and generate an alert when traffic in one of the monitored views
meets the specified criteria. A non-administrative user can create sentries,
however, only an administrative user can configure advanced sentries on a
system-wide basis.
Note:
For information on creating system-wide sentries, see the STRM
Administration Guide.
Alert details appear in the appropriate location of the Offense Manager as follows:
•
If you create a Threshold, Anomaly, or Behavioral sentry that generates an
alert, the details appear in the Network Anomalies interface as these type of
alerts are monitoring time series event data. You can also distribute alert
notifications to a syslog file, e-mail, or run a custom script.
•
If you create a Security/Policy sentry with the auto learn option selected, the
alerts appear in the Network Anomalies interface. You can also distribute alert
notifications to a syslog file, e-mail, or run a custom script.
•
If you create a Security/Policy sentry without the auto learn option selected, the
generated alerts appear in the offenses portion of the Offense Manager,
depending on the chosen event categories. If you wish to configure notifications
for this sentry type, you must use the custom rules wizard. For more
information, see the
STRM Administration Guide
.
This chapter provides information on managing sentries including:
•
About Sentries
•
Viewing Sentries
•
Creating a Sentry
•
Editing a Sentry
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......