STRM Users Guide
Creating a Sentry
51
Alert sensitivity
Specify the sensitivity (1 to 100) level for this alert. This
level indicates how far outside the predicted values before
a violation generates. A value of 1 indicates the measured
value cannot be outside the predicted value and a value of
100 indicates the traffic is more than four times larger than
the predicted value.
For example, the level of alert sensitivity depends on the
traffic experienced by your network. If your network is
noisy, as shown in the graph below, you may wish to set
your sensitivity to a higher level.
If your network displays consistent traffic, as shown below,
you may wish to configure the alert sensitivity to a lower
level.
Table 4-6
Behavior Sentry Parameters (continued)
Parameter
Action
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......