STRM Users Guide
Creating a Sentry
71
Step 11
Click
Next
.
The Sentry Response window appears.
Step 12
Enter values for the following parameters:
Weight
Specify the relative importance of this sentry. This
determines the ranking that the generated event displays
in the Offense Manager.
STRM uses the following formula to calculate the weight:
(sentry network object weight)/3/time
difference
Where time difference is:
1 + (second since the sentry alerted / 10,000,000,000)
Save as package
Select the check box if you wish to save this sentry as a
package to use with other sentries. By default, the check
box is clear. Specify the following:
•
Package Name
- Specify the name you wish to assign
to this package.
•
Package Description
- Specify a description for the
package.
•
Share Package
- Click
Share Package
to share this
package with other STRM users.
Minimum Activations
Before Alert
Specify the minimum number of times you wish this
activity to occur before an alert generates.
Delay Between Alerts
Specify the number of intervals, after of the first
occurrence of this alert, before the next occurrence of this
event.
Maximum responses per
event
Specify the maximum number of times you wish this event
to generate.
Sharing
Click
Share Sentry
to access the Select Users window,
which allows you to indicate any users you wish to share
this sentry.
Table 4-18
Sentry Attributes Parameters (continued)
Parameter
Action
Table 4-19
Sentry Response Parameters
Parameter Sub-Parameter Action
Email Subject
Specify a subject for the notification e-mail sent by the
sentry engine.
Recipient(s)
Specify the recipient(s) of the notification e-mail sent
by the sentry engine. Separate multiple entries with a
comma.
Format
Specify the amount of text included in the e-mail.
Options include: Subject Only, Brief, Detailed - Text,
Detailed - HTML.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......