18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 18: Monitoring<br />

Viewing IPS attack and system event summaries<br />

524<br />

Figure 219: Audit<br />

Record window<br />

About the Audit<br />

Record window<br />

When you double-click an audit event in the table, the detailed audit<br />

information for that attack appears in a pop-up window. The displayed fields<br />

vary, depending on the audit type. In general, the data in an audit message is a<br />

tag name followed by a colon and the tag’s value. The following table provides<br />

examples and descriptions <strong>of</strong> fields that may appear in an audit record.<br />

More information on audit fields is available using acat -c |more at a<br />

command line interface and in the <strong>Sidewinder</strong> Export Format application note<br />

at www.securecomputing.com/goto/appnotes.<br />

Table 32: Audit data field examples<br />

Tag Description<br />

facility The event facility code for the event that audited the message,<br />

such as the kernel or FTP<br />

area The area in the facility that audited the message, such as<br />

a_nil_area or a_proxylib<br />

type The event type code, such as t_attack<br />

category The event category code, such as c_policy_violation<br />

priority The event priority, such as p_major<br />

*id IDs that may appear include the process ID (pid), the real user<br />

ID (ruid), the effective user ID (euid), the process family ID (fid)<br />

and login ID (logid)<br />

srcservice/<br />

destservice<br />

srcburb/<br />

destburb<br />

The source or destination service name (/etc/services)<br />

The source or destination burb number<br />

reason The reason the <strong>Sidewinder</strong> <strong>G2</strong> generated an audit record

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!