STRM Users Guide
78
I
NVESTIGATING
O
FFENSES
•
Marking an Item For Follow-Up
•
Configuring Notification
•
Managing Network Anomalies
•
Exporting Offenses
Using the Offense
Manager
Using the Offense Manager interface, you can access the following options for
managing security and policy events, behaviors, anomalies, targets, and attackers
on your network:
Managing My
Offenses
Users with the appropriate privileges can assign offenses to users. All offenses
assigned to you will appear in the My Offenses Interface. By default, the My
Offenses interface appears when you click the Offense Manager tab, however, if
no offenses are assigned to you, the All Offenses interface appears.
To view offenses assigned to you:
Step 1
Click the
Offense Manager
tab.
The Offense Manager window appears.
Step 2
Click
My Offenses
from the navigation menu.
Table 5-1
Offense Manager Interface Options
Menu
Description
My Offenses
Includes a list of all offenses that have been assigned to you by the
administrator.
All Offenses
Includes all global offenses on the network.
By Category
Includes a summary view of all offenses based on the high and
low-level category. For more information on high and low-level
categories, see the
Event Category Correlation Reference Guide
.
For information on investigating category offenses, see the
Category Offense Investigation Guide
.
By Attacker
Includes all offenses by attacker or source. Each offense includes
both security and policy issues, where source relates to policy
issues. For more information, see
Managing Offenses By
Attacker
.
By Target
Includes all offenses by local targets or destination. For more
information, see
Managing Offenses By Targets
.
By Network
Includes all offenses by networks. For more information, see
Managing Offenses By Networks
.
Network
Anomalies
Includes information on offenses generated from sentries. For
more information, see
Managing Network Anomalies
.
Rules
Allows you to create custom rules. For more information, see the
STRM Administration Guide.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......