18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring alarm events and event responses<br />

17-8 Alarm Events and Responses<br />

8. Select the Reset Event Count on Threshold check box if you want the<br />

event count to be reset and the audit list cleared each time the<br />

threshold number is reached within the specified time period.<br />

Note: If you de-select this check box, when the threshold number is reached, the<br />

event count will not be reset, and the event list will not be cleared. This may cause the<br />

same audit events to be used to generate additional alarms.<br />

9. Select the Perform Strikeback if Alarm Dropped check box to run the<br />

Strikeback commands you have configured for each alarm event that<br />

occurs within the alarm interval (rather than only when the number <strong>of</strong><br />

events reaches the threshold value and triggers an additional alarm).<br />

Note: If you de-select this check box, Strikeback commands will be performed only<br />

when an event response is triggered.<br />

10. In the Strikeback Percentage Threshold field, type the percentage <strong>of</strong><br />

threshold alarm events that must be initiated from a single source<br />

address before a Strikeback will occur. This allows you to configure<br />

Strikebacks to occur only on source addresses that initiate a certain<br />

percentage <strong>of</strong> events, and prevents the system from extraneously<br />

performing Strikebacks on simple error events (such as a single bad<br />

login attempt by a user) when the threshold is reached.<br />

11. Click Add to add the new alarm event. (If you are modifying an alarm<br />

event, click OK to save your changes.)<br />

12. To add another alarm event, repeat the above procedure.<br />

Displaying and configuring event responses<br />

Event responses are used to specify an appropriate response when an<br />

alarm is triggered in your system. The <strong>Sidewinder</strong> <strong>G2</strong> is preconfigured<br />

with several default responses.<br />

To view the default responses and to add or modify event responses,<br />

click the Event Responses tab on the Alarm Configuration window. The<br />

Event Responses tab appears.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!