18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

17<br />

Configuring alarm events and event responses<br />

Figure 17-1. Alarm Event<br />

List<br />

About the Alarm Event List<br />

tab<br />

17-2 Alarm Events and Responses<br />

Alarm events are generated on the <strong>Sidewinder</strong> <strong>G2</strong> using a daemon<br />

called auditbotd. This daemon listens to the audit device and detects<br />

various types <strong>of</strong> alarm events (also known as "auditbots") as they<br />

occur. Alarm events are defined in the /etc/sidewinder/<br />

audit_filters.conf file.<br />

Tip: Default Strikeback event responses are automatically configured on the <strong>Sidewinder</strong><br />

<strong>G2</strong> during initial configuration. See “Configuring alarm events” on page 17-6.<br />

Configuring alarm events<br />

To view or configure alarm events, start the Admin Console and select<br />

Reports & Monitoring -> Alarm Configuration. The Alarm Configuration<br />

window appears. This window contains two tabs that are used to<br />

enter information about an alarm event. The Alarm Event List tab<br />

(described below), and the Event Responses tab (described in<br />

“Displaying and configuring event responses” on page 17-8).<br />

Note: To view all event settings, use the scroll bar or resize the window.<br />

This tab allows you to view the list <strong>of</strong> currently configured alarm<br />

event types. The following table describes the fields displayed for<br />

each alarm event in the table.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!