Symantec 10268947 User Guide - Page 82

About console response action

Page 82 highlights

82 Response Rules About response actions Note: This response action records only fully assembled packets from actual flows, not malformed packets or packet fragments. You can view detected packet contents in the Advanced tab of Event Details. See "Viewing event details" on page 197. About console response action Symantec Network Security can initiate an action on the Network Security console in response to an attack. A SuperUser or Administrator can configure the response rule to play an alert sound and/or to execute a program on the Network Security console. Any user can enable each Network Security console individually to execute console response actions. The minimum delay between responses is 1 minute. Enabling console response actions You must enable console response actions on each Network Security console individually. To enable specific console response actions 1 In the Network Security console, click Configuration > Response Rules. 2 In Response Rules, click Configuration > Console Response Configuration. 3 In Local Console Configuration, choose from the following checkboxes: ■ Play Alert Sounds: Click this to enable this Network Security console to emit an alert sound when triggered by an event. ■ Execute Programs: Click this to enable this Network Security console to perform the console response action. 4 In Local Console Configuration, click OK to save and close. Note: The Network Security console must be running in order for Symantec Network Security to execute the console response action. If a Network Security console starts after console response events are sent, it does not execute the actions. Instead, upon startup, it displays a prompt indicating that the actions did not execute. About export flow response action The export flow response action exports matching flows stored in the flow data store. The action is based on the characteristics of the triggering events, which

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

82
Response Rules
About response actions
Note:
This response action records only fully assembled packets from actual
flows, not malformed packets or packet fragments. You can view detected
packet contents in the Advanced tab of Event Details.
See
“Viewing event details”
on page 197.
About console response action
Symantec Network Security can initiate an action on the Network Security
console in response to an attack. A SuperUser or Administrator can configure
the response rule to play an alert sound and/or to execute a program on the
Network Security console. Any user can enable each Network Security console
individually to execute console response actions. The minimum delay between
responses is 1 minute.
Enabling console response actions
You must enable console response actions on each Network Security console
individually.
To enable specific console response actions
1
In the Network Security console, click
Configuration
>
Response Rules
.
2
In
Response Rules
, click
Configuration
>
Console Response Configuration
.
3
In
Local Console Configuration
, choose from the following checkboxes:
Play Alert Sounds
: Click this to enable this Network Security console
to emit an alert sound when triggered by an event.
Execute Programs
: Click this to enable this Network Security console
to perform the console response action.
4
In
Local Console Configuration
, click
OK
to save and close.
Note:
The Network Security console must be running in order for Symantec
Network Security to execute the console response action. If a Network
Security console starts after console response events are sent, it does not
execute the actions. Instead, upon startup, it displays a prompt indicating
that the actions did not execute.
About export flow response action
The export flow response action exports matching flows stored in the flow data
store. The action is based on the characteristics of the triggering events, which