Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - MANAGING SENSOR DEVICES REV 1 Manual page 9

Managing sensor devices
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - MANAGING SENSOR DEVICES REV 1:
Table of Contents

Advertisement

Table 1-1 Add a Sensor Device Parameters
Parameter
Device Name
Sensor Device Type
Protocol Configuration
Device Description
Device Hostname/IP
Credibility
Target Event Collector
Coalescing Events
Store Event Payload
Managing Sensor Devices Guide
Description
Specify the desired name of the device.
Using the drop-down list, select the type of sensor
device you wish to add.
Using the drop-down list box, select the protocol you
wish to use for this sensor device. If the device uses
syslog, a default syslog configuration is automatically
applied. For more information on configuring protocols,
Adding a Protocol
see
Specify a description for the sensor device (optional).
Specify the hostname or IP address for the device. If
you wish to add the device using the hostname, please
note that you must enter the hostname as it exactly
appears in the logs sent to STRM Log Management.
Otherwise, STRM Log Management will not process
the events.
Specify the credibility of the device. The range is from 0
to 10. The credibility indicates the integrity of an event
or offense as determined by the credibility rating from
source devices. Credibility increases if multiple sources
report the same event. The default is 5.
Using the drop-down list box, select the Event Collector
you wish to use as the target for this device.
Enables or disables the ability of a sensor device to
coalesce (bundle) events. The default is Yes.
By default, all auto detected sensor devices use the
value configured in the Coalescing Events parameter in
the STRM Settings window. However, when you create
a new sensor device or update the configuration for an
auto detected sensor device, the value configured in
the individual sensor device is the value used by the
sensor device. For more information, see the STRM
Log Management Administration Guide.
Enables or disables the ability for a sensor device to
store event payload information. The default is Yes.
By default, all auto detected sensor devices use the
value configured in the Store Event Payload parameter
in the STRM Settings window. However, when you
create a new sensor device or update the configuration
for an auto detected sensor device, the value
configured in the individual sensor device is the value
used by the sensor device. For more information, see
the STRM Log Management Administration Guide.
Managing Sensor Devices
.
5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Security threat response manager

Table of Contents