Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 Administration Manual page 41

Strm administration guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2:
Table of Contents

Advertisement

Table 3-3 STRM Settings Parameters (continued)
Parameter
Offense Retention Period Using the drop-down list box, select the period of time you
Identity History Retention
Period
Attacker History Retention
Period
Ariel Database Settings
Flow Data Storage
Location
Flow Data Retention
Period
Asset Profile Storage
Location
Asset Profile Retention
Period
Device Log Storage
Location
Device Log Data
Retention Period
Custom View Retention
Period
Maximum Real Time
Results
Reporting Max Matched
Results
Command Line Max
Matched Results
Web Execution Time Limit Specify the maximum amount of time, in seconds, you
Reporting Execution Time
Limit
Command Line Execution
Time Limit
Flow Log Hashing
STRM Administration Guide
Description
wish to retain offense information. The default is 3 days.
Using the drop-down list box, select the length of time you
wish to store asset profile history records. The default is
30 days
Specify the amount of time that you wish to store the
attacker history. The default is 6 months.
Specify the location that you wish to store the flow log
information. The default location is /store/ariel/flows.
Specify the period of time you wish to store flow data. The
default is 1 week.
Specify the location that you wish to store the asset profile
storage location. The default location is /store/ariel/hprof.
Specify the period of time, in days, that you wish to store
the asset profile information. The default is 30 days.
Specify the location that you wish to store the device log
information. The default location is /store/ariel/events.
Specify the amount of time that you wish to store the
device log data. The default is 30 days.
Specify the amount of time, in seconds, that you wish to
store custom view information. The default is 2592000
seconds.
Specify the maximum number of results you wish to view
in the Event Viewer and Flow Viewer. The default is
10000.
Specify the maximum number of results you wish a report
to return. This value applies to the search results in the
Event Viewer and Flow Viewer. The default is 1000000.
Specify the maximum number of results you wish the
command line to return. The default is 0.
wish a query in the interface to process before a time out
occurs. This value applies to the search results in the
Event Viewer and Flow Viewer. The default is 600
seconds.
Specify the maximum amount of time, in seconds, you
wish a reporting query to process before a time out
occurs. The default is 57600 seconds.
Specify the maximum amount of time, in seconds, you
wish a query in the command line to process before a
time out occurs. The default is 0 seconds.
Enables or disables the ability for STRM to store a hash
file for every stored flow log file. The default is No.
Configuring STRM Settings
33

Advertisement

Table of Contents
loading

Table of Contents