STRM Users Guide
56
M
ANAGING
S
ENTRIES
Creating an Anomaly
Sentry
An anomaly sentry monitors your deployment for any abnormal activity. This sentry
generates an alert in one of the following situations:
•
If a consistently inactive object becomes active.
•
If a consistently active object becomes inactive.
•
If an object is consistently active, a certain percentage of the time experiences
a change in activity.
For example, if you configure an Anomaly sentry with the following values:
•
Large Window: 1 Day
•
Small Window: 1 Hour
•
Percent change required to alert: 50
•
Condition for alert: 25% + 12.5% = 37.5%
If the SSH server is typically used for 15 minutes out of every hour and the server
becomes active for more than 22.5 minutes in an hour, an alert generates.
To create an anomaly sentry:
Step 1
Click the
Network Surveillance
tab.
The Network Surveillance interface appears.
Step 2
Navigate to the appropriate view you wish the sentry to apply.
For information on navigating views, see
Chapter 3 Managing Your Network
Activity
.
Note:
You cannot create a sentry in the ByNets view. You must navigate to a
non-related view to create a sentry.
Step 3
Below the graph, click
Add Sentry
.
The Add Sentry Wizard appears.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......