Tuning False
Positives
Step 1
Step 2
Step 3
Step 4
Step 5
You can use the Event Viewer to tune out False Positive events from created
offenses in STRM by using the False Positive Tuning function. You must have
appropriate permissions for creating customized rules to tune false positives. For
more information on roles, see the STRM Administration Guide. You can tune false
positive events from any summary or details panel.
To tune a false positive event:
Click the Event Viewer tab.
The Event Viewer window appears.
Select the event you wish to tune.
Click
False Positive.
The False Positive window appears with information derived from the selected
event.
Select one of the following Event Property options:
Events with a specific QID of <Event>
•
Any Events with a low level category
•
Any Events with a high level category
•
Any Events
•
Select one of the Traffic Direction options:
<Source IP Address> to <Destination IP Address>
•
<Source IP Address> to Any Destination
•
Any Source to <Destination IP Address>
•
Any Source to any Destination
•
STRM Users Guide
Tuning False Positives
151