Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT REV 1 Manual page 112

Strm log management users guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT REV 1:
Table of Contents

Advertisement

106
D
R
EFAULT
ULES AND
Table B-7 Default Building Blocks (continued)
Building Block
Default-BB-FalsePositive:
Internal Attacker to
Internal Target False
Positives
Default-BB-FalsePositive:
Internal Attacker to
Remote Target False
Positives
Default-BB-FalsePositive:
LDAP Server False
Positive Categories
Default-BB-FalsePositive:
LDAP Server False
Positive Events
Default-BB-FalsePositive:
Mail Server False Positive
Categories
Default-BB-FalsePositive:
Mail Server False Positive
Events
Default-BB-FalsePositive:
Network Management
Servers Recon
Default-BB-FalsePositive:
Proxy Server False
Positive Categories
Default-BB-FalsePositive:
Proxy Server False
Positive Events
B
B
UILDING
LOCKS
Block
Group
Type
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
False
Event Edit this BB to define all the false
Positive
STRM Log Management Users Guide
Description
positive QIDs that occur to or from
Local-to-Local (L2L) based
servers.
positive QIDs that occur to or from
Local-to-Remote (L2R) based
servers.
positive categories that occur to or
from LDAP servers that are
defined in the
Default-BB-HostDefinition: LDAP
Servers building block.
positive QIDs that occur to or from
LDAP servers that are defined in
the Default-BB-HostDefinition:
LDAP Servers building block.
positive categories that occur to or
from mail servers that are defined
in the Default-BB-HostDefinition:
Mail Servers building block.
positive QIDs that occur to or from
mail servers that are defined in the
Default-BB-HostDefinition: Mail
Servers building block.
positive categories that occur to or
from network management servers
that are defined in the
Default-BB-HostDefinition:
Network Management Servers
building block.
positive categories that occur to or
from proxy servers that are defined
in the Default-BB-HostDefinition:
Proxy Servers building block.
positive QIDs that occur to or from
proxy servers that are defined in
the Default-BB-HostDefinition:
Proxy Servers building block.
Associated Building
Blocks, if applicable
Default-BB-HostDefinition:
LDAP Servers
Default-BB-HostDefinition:
LDAP Servers
Default-BB-HostDefinition:
Mail Servers
Default-BB-HostDefinition:
Mail Servers
Default-BB-HostDefinition:
Network Management
Servers
Default-BB-HostDefinition:
Proxy Servers
Default-BB-HostDefinition:
Proxy Servers

Advertisement

Table of Contents
loading

Table of Contents