Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT REV 1 Manual page 51

Strm log management users guide
Hide thumbs Also See for SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT REV 1:
Table of Contents

Advertisement

Table 4-1 Functions Group (continued)
Test
Description
Multi-Rule
You can also use building
Function
blocks or existing rules to
populate this test. Allows you to
detect the selected rules with
same source information across
more than the configured
number of destinations within a
configured time period.
Step 9
Step 10
Step 11
In the groups area, select the check box(es) of the groups to which you wish to
assign this rule. For more information on grouping rules, see
In the Notes field, enter any notes you wish to include for this rule. Click Next.
The Rule Responses window appears, which allows you to configure the action
STRM Log Management takes when the event sequence is detected.
Configure the following parameters:
STRM Log Management Users Guide
Default Test Name
when any of these
rules with the same IP
address/Port/QID/
Event/Device/
Category more than 5
times, across more
than 5 IP address/
Port/QID/Event/
Device/Category
within 10 minutes
Creating a Rule
Parameters
Configure the following parameters:
rules - Specify the rules you wish
this test to consider.
IP address/Port/QID/
Event/Device/ Category - Specify
whether you wish this rule to
consider a source IP address,
source port, QID, device event ID,
device, or category.
5 - Specify the number of rules you
wish this test to consider.
more than - Specify if you wish
this test to consider more than or
exactly the number of destination
IP address(es), destination port(s),
QID(s), Device Event ID(s), or
Device(s).
5 - Specify the number of IP
addresses, ports, QIDs, events,
devices, or categories you wish
this test to consider.
IP address/ Port/QID/Event/
Device/Category - Specify the
destination you wish this test to
consider. The options are:
anything, destination IP(s),
destination port(s), QID(s), Device
Event ID(s), or Device(s).
10 - Specify the time value you
wish to assign to this test.
minutes - Specify the time
measurement value, seconds,
minutes, hours, or days that you
wish to apply to this test.
Grouping
45
Rules.

Advertisement

Table of Contents
loading

Table of Contents