149
Responding
Setting response actions
The following is an example of a custom response command:
/usr/local/bin/myscript.sh -i %i -t %t -s %s [email protected]
The following table describes the variables that can be used in the command line
of custom response actions, console response actions, and email responses:
Preventing logging of passwords in cleartext
To prevent logging of passwords in cleartext, preface the password with a %*
character sequence. Make sure to put the password directly after the %* with no
spaces in between. For example, for the following password:
&*%arG
prepend the password as follows:
%*&*%arG
Table 6-1
Response Variables
Variable
Value
%c
Indicates the event class, such as Sensor or Notice.
%d
Indicates a comma-delimited list of destination IP addresses and ports in
the following format:
<IP address>:port
. Some attacks, such as syn
floods, may have multiple destinations.
%D
Device name; for example:
hub4
.
%F
Flowcookie; for example:
IP%COUNTER%172.16.32.236:0/192.168.0.162:0#255
%I
The user-assigned name of the interface or interface group where the
attack was detected.
%m
MAC address of the source, if available; otherwise left blank.
%s
Indicates a comma-delimited list of source IP addresses and ports in the
following format:
<IP address>:port
. Some attacks, such as syn floods,
may have multiple sources.
%t
Indicates a specific base event type, displayed in the Network Security
console with a human-readable name; for example,
Fragmentation
Attack
.
%T
Indicates when the first event was detected for the incident. Date and time
appears in human-readable format.
%v
Indicates the VLAN number of the destination, if available; otherwise -1.
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...