Symantec 10268947 User Guide - Page 76

Searching event types, About response parameters, About event targets, Configuration, Response Rules

Page 76 highlights

76 Response Rules About automated responses Searching event types All users can view a more manageable subset of the entire event list by using any or all of the search criteria to shorten the list of event types in the Search Event List. To select event types 1 In the Network Security console, click Configuration > Response Rules > Event Type. 2 To see the Event Lists, double-click Event Types. 3 In Search Events, provide some or all of the following search criteria: ■ Click Title to identify the search. ■ Click Protocol to search for specific protocols. ■ Click Category to search for specific categories. ■ Click Severity to indicate the severity level. ■ Click Confidence to indicate the confidence level. ■ Click Intent to indicate the intent. 4 After selecting search criteria, click Search Events. About response parameters In Configuration > Response Rules, SuperUsers and Administrators can edit and configure response rule parameters to specify the characteristics of the events and incidents that Symantec Network Security responds to. Each response rule contains the following response parameters: ■ About event targets ■ About event types ■ About severity levels ■ About confidence levels ■ About event sources ■ About response actions ■ About next actions About event targets The event target parameter specifies the location where the detected incident occurs. The possible values for this parameter include the locations, network

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

76
Response Rules
About automated responses
Searching event types
All users can view a more manageable subset of the entire event list by using any
or all of the search criteria to shorten the list of event types in the Search Event
List.
To select event types
1
In the Network Security console, click
Configuration
>
Response Rules
>
Event Type
.
2
To see the Event Lists, double-click
Event Types
.
3
In
Search Events
, provide some or all of the following search criteria:
Click
Title
to identify the search.
Click
Protocol
to search for specific protocols.
Click
Category
to search for specific categories.
Click
Severity
to indicate the severity level.
Click
Confidence
to indicate the confidence level.
Click
Intent
to indicate the intent.
4
After selecting search criteria, click
Search Events
.
About response parameters
In Configuration > Response Rules, SuperUsers and Administrators can edit and
configure response rule parameters to specify the characteristics of the events
and incidents that Symantec Network Security responds to.
Each response rule contains the following response parameters:
About event targets
About event types
About severity levels
About confidence levels
About event sources
About response actions
About next actions
About event targets
The event target parameter specifies the location where the detected incident
occurs. The possible values for this parameter include the locations, network