214 Monitoring
Tuning incident parameters
2
In Symantec Network Security Configuration Parameters, click
Incident/Event Parameters
>
Incident Idle Time
.
3
Enter a value for the parameter, in minutes. By default, the value for this
parameter is set to 10 minutes.
4
Click
OK
to save and exit.
Caution:
You will lose any unsaved changes when you exit.
Setting Maximum Incidents
Maximum Incidents
determines the maximum number of incidents allowed to be
active at a given time.
The default value is 50. Raise the value if you expect to see traffic streams with
more than 50 attacks at the same time.
To configure this parameter
1
Click
Configuration
>
Node
>
Network Security Parameters
.
2
In
Select Node
, choose the node from the pull-down list, and click
OK
.
3
In the left pane, click
Maximum Incidents
.
4
In the lower right pane, enter the number of incidents.
5
Click
Apply
.
6
In
Apply Changes To
, select the node to which to apply the parameter.
7
Click
OK
to save the changes to this node and close.
Note:
We recommend that this value be set between 10 and 100. Increasing this
value can impact memory.
Setting Maximum Active Incident Life
Maximum Active Incident Life
determines how long an incident remains active,
before it is retired. This refreshes the aggregation statistics on a long-running
incident, and prevents the incident definition from becoming diffuse. If an
incident receives events after retirement, a new incident immediately forms so
that no events are lost. The default value is 6 hours.
To configure this parameter
1
Click
Configuration
>
Node
>
Network Security Parameters
.
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...