STRM Users Guide
72
M
ANAGING
S
ENTRIES
Step 13
Review the sentry details. Click
Finish
.
Editing a Sentry
You can only edit sentries that you have created. To edit a sentry:
Step 1
Click the
Network Surveillance
tab.
The Network Surveillance interface appears.
Step 2
Below the graph, click
View Sentries
.
The Sentry List window appears.
Step 3
Click the sentry you wish to edit.
The sentry details appear.
Trigger
Trigger Script
Using the drop-down list box, specify the action you
wish the sentry engine to perform. The options include:
•
Trigger Script
- Specify if you wish this sentry to
use the following:
SNMP traps
- Sentry engine sends an SNMP Trap
notification.
Block IPs
- Sentry engine blocks specific IP
addresses.
•
Parameters
- Specify the parameters required to
trigger either the SNMP trap, or to block IP
addresses.
Note:
These default scripts need to be customized for
proper use in your environment. To edit the script, use
SSH to login to your STRM Console and edit the
scripts in the /opt/qradar/triggerbin directory. For
assistance, contact your local administrator.
Syslog
Select the check box if you wish to save the sentry
event log file to the syslog server.
Table 4-19
Sentry Response Parameters (continued)
Parameter Sub-Parameter Action
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......