136 Responding
Setting response parameters
Setting response parameters
In Configuration > Response Rules, SuperUsers and Administrators can edit and
configure response rule parameters to specify the characteristics of the events
and incidents that Symantec Network Security responds to.
Each response rule contains the following response parameters:
■
Setting event targets
■
Setting event types
■
Setting severity levels
■
Setting confidence levels
■
Setting event sources
■
Setting response actions
■
Setting next actions
Setting event targets
The event target parameter specifies the location where the detected incident
occurs. The possible values for this parameter include the locations, network
segments, and network border interfaces defined in the network topology
database.
Note:
SuperUsers and Administrators can apply the response rule to a specific
location or interface in the network using Event Target.
To set the Event Target
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
Click the
Event Target
cell of the response policy table row.
3
In
Select Event Target
, select the locations, network segments, and/or peer
interfaces to which the response rule will apply, and click
OK
.
See
“Adding nodes and objects”
on page 83.
Setting event types
The event type parameter specifies the base event or events for which the
response rule is defined. Event types are grouped into several larger protocol
and service attack categories. When Symantec Network Security detects a
suspicious event, it analyzes the event to match it to an event type.
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...