STRM Users Guide
58
M
ANAGING
S
ENTRIES
Table 4-9
Anomaly Sentry Parameters
Parameter
Action
Large Window
Specify an extended period of time you wish the system to
monitor flows in your network. This allows the system a
basis of comparison for traffic over an extended period of
time. If the large window and small window values exceed
a certain threshold, the sentry generates an alert.
We recommend that you include at least two cycles for
comparison. For example, if your network is experiences
high traffic volume during the day but less traffic at night,
you should set this parameter to at least two cycles for
comparison.
Small Window
Specify a period of time you wish the system to monitor
flows in your network. This allows the system a basis of
comparison for traffic over an smaller period of time. If the
large window and small window values exceed a certain
threshold, the sentry generates an alert.
We recommend that you set the small window to at least
twice as large as a typical burst of traffic. For example, if
your network experiences bursts of traffic that exist for 30
minutes, set this value to at least 1 hour.
Percent change
required to alert
Specify the percentage change in behavior this view must
experience before the sentry generates an alert. For a low
activity network, set this value to a high value. For a high
activity network, set this to a low percentage value.
Layer
Specifies the property and measurement used in the Y-axis
of the Network Surveillance graphs. The current value
being used to draw the graphs is displayed in red in the
Layers console. The values that can be used include bytes,
packets, number of hosts, and others.
Direction
Specify the direction of traffic you wish this sentry to
monitor. The options are In, Out, or Both.
Test as group
Select the check box if you wish all objects to add together
to be tested. For example, when selected, the top line of
the graph is evaluated as a group. If the check box is clear,
you wish all objects to be tested independently.
Date is relevant
Select the check box if you wish this sentry to consider
date. When selected, date fields appear. Enter the relevant
dates you wish this sentry to monitor. By default, the check
box is clear.
Day of week is relevant Select the check box if you wish this sentry to consider the
day of the week. When selected, the day of the week fields
appear. Using the drop-down list boxes, select the relevant
days you wish this sentry to consider. By default, the check
box is clear.
Time of day is relevant
Select the check box if you wish this sentry to consider the
time of day. When selected, the time of day fields appear.
Using the drop-down list box, select the time of day you
wish this sentry to consider.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......