13.07.2015 Views

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

TRITON - Web Security Help, Version 7.7 - Websense

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Web</strong> <strong>Security</strong> Server Administration2. Set the Threshold by selecting the number of requests that cause an alert to begenerated.3. Select each desired alert method (Email, SNMP) for these protocols.Only the alert methods that have been enabled on the Alerts page (see Configuringgeneral alert options, page 389) are available for selection.4. Click OK to cache changes and return to the Protocol Usage page (seeConfiguring protocol usage alerts, page 393). Changes are not implemented untilyou click Save and Deploy.Configuring suspicious activity alerts<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> | <strong>Web</strong> <strong>Security</strong> Solutions | <strong>Version</strong> <strong>7.7</strong>.xRelated topics: Alerting, page 388 Flood control, page 389 Configuring general alert options, page 389<strong>Web</strong>sense software can notify you when suspicious activity of a specified severitylevel reaches a defined threshold. You can define alerts for permitted requests andblocked requests of each severity level.Because Content Gateway is required to detect critical and high severity alerts, it isnot possible to configure alerting for those severity levels in <strong>Web</strong>sense <strong>Web</strong> <strong>Security</strong>and <strong>Web</strong>sense <strong>Web</strong> Filter deployments.Use the Settings > Alerts > Suspicious Activity page to enable, disable, or changealerting configuration for alerts associated with suspicious events in your network.Detailed information about these events is displayed on the Threats dashboard.The page displays 2 tables: Permitted Suspicious Activity Alerts and BlockedSuspicious Activity Alerts. Each table shows:The Severity level to be configured. The 4 severity levels are critical, high,medium, and low. Severity level is determined by the threat category associatedwith the alert. See How severity is assigned to suspicious activity, page 39, formore information.The alerting Threshold. By default, the threshold for critical and high severityalerts, both permitted and blocked, is 1.One or more notification methods. Suspicious activity alerts can be sent viaEmail, SNMP, or both.Whether or not the alert is Enabled. A green check mark indicates that alerts arebeing generated for suspicious activity of the selected severity. A red “X”indicates that alerting is disabled for the selected severity.To update suspicious activity alert settings, you can:<strong>TRITON</strong> - <strong>Web</strong> <strong>Security</strong> <strong>Help</strong> 395

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!