Juniper SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - REV1 Manual page 147

Table of Contents

Advertisement

Table 6-7 Aggregate Normalized Events (continued)
Aggregate Option
Relevance
Username
Device
Device Type
Device Group
Network
Src IP/ Dst IP / Dst
Port/ User
Src IP/ Dst IP / Dst
Port/ Event Name
Src IP/ Event Name/
User
Src IP/ Dst IP/ Event
Name/ User
Src IP/ Dst IP/ User
Src IP / Dst IP
Dst IP/ Port
Event Name/ Device
Device/ High Level Cat Displays a summarized list of events grouped by the device
Device/ High Level
Cat./ Low Level Cat.
Matched Custom Rule
STRM Users Guide
Description
Relevance indicates the significance of an event. This option
displays a summarized list of events grouped by the
relevance of the event.
Displays a summarized list of events grouped by the
username associated with the events.
Displays a summarized list of events grouped by the devices
that sent the event to STRM.
Device Type indicates the type of device that originated the
event. This aggregate option displays a summarized list of
events grouped by device type.
Displays a summarized list of events grouped by device
group.
Displays a summarized list of events grouped by the network
associated with the event.
Displays a summarized list of events grouped by the source
IP address, destination IP address, destination port, and the
user.
Displays a summarized list of events grouped by the source
IP address, destination IP address, destination port, and the
name of the event.
Displays a summarized list of events grouped by the source
IP address, event name, and user.
Displays a summarized list of events grouped by the source
IP address, destination IP address, event name, and user.
Displays a summarized list of events grouped by the source
IP address, destination IP address , and the username
associated with the event.
Displays a summarized list of events grouped by traffic from
the source IP address to destination IP address.
Displays a summarized list of events grouped by destination
IP address and port.
Displays a summarized list of events grouped by the event
name and the device that sent the event to STRM.
that sent the event to STRM and the high-level category.
For more information on categories, see the Event Category
Correlation Reference Guide.
Displays a summarized list of events grouped by the device
that sent the event to STRM and the high and low-level
categories.
Displays a summarized list of events grouped by the
associated custom rule.
Viewing Events
141

Advertisement

Table of Contents
loading

This manual is also suitable for:

Security threat response manager 2008.2 r2

Table of Contents