Viewing signatures
All users can view all available PAD event types and user-defined signatures
from the Policies tab. You can also see which signatures are applied to the
monitoring interfaces, interface pairs, or interface groups, as well as the list of
signature variables.
To see interfaces
On the Policies tab, click Policies > Policies Applied to Interfaces to see
◆
interfaces with policies applied.
To see applied signatures
On the Policies tab, click Policies > Policies to see the Symantec signatures
◆
that are applied.
To see available signatures
On the Policies tab, click the User-defined Signatures tab to see available
◆
user-defined signatures.
To see signature variables
On the Policies tab, click the Signature Variables tab to see available
◆
variables to use when defining signatures.
Adding or editing user-defined signatures
The Network Security console provides a way to customize Symantec Network
Security to specific environments by creating user-defined signatures to match
network traffic.
To add or edit a user-defined signature
1
On the Policies tab, do one of the following:
Click User-defined Signatures > New.
■
Select an existing user-defined signature and click User-defined
■
Signatures > Edit.
2
In Add User-defined Signature or Edit User-defined Signature, provide
information for the following fields:
In Title, enter a name for the user-defined signature.
■
In Severity, enter a level from the pull-down list.
■
In Confidence, enter a level from the pull-down list.
■
In Category, enter a type of event from the pull-down list.
■
In Intent, enter an intention from the pull-down list.
■
Detecting
Configuring signature detection
181