HP X Unified Security Platform Series Uživatelský manuál Strana 309

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 333
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 308
Log Formats
X Family LSM User’s Guide V 2.5.1 293
Comp Software component that generated the message:
ALT
= Alert Log
BLK
= IPS Block Log
Message
(Contained
within
quotes.)
Alert Action
Alert
= for Alert Log
Block
= for IPS Block Log
Policy Log Version
v4
Alert Type A bit field that identifies a message as traffic threshold,
invalid, etc.
Policy UUID ID for the policy, enclosed within brackets ([]).
Default policies begin with “
[00000002-
...
Message Severity
1
= low
2
= minor
3
= major
4
= critical
Signature UUID Signature ID from the DV, enclosed within brackets
([]). Can you have multiple policies per signature.
Default signatures begin with “
[00000001-
...
Protocol Protocol of the alert.
Examples:
HTTP
,
IP
,
TCP
,
IDP
, and
ICMP
.
IP Protocol Numeric Layer 2 protocol (uint). Only used in Firewall Block
Logs for the X family device. In all other logs, this field
will be
0
.
IP Protocol String Layer 2 protocol (string). Only used in Firewall Block
Logs for the X family device. In all other logs, this field
will be blank.
Source IP Address and
Port
Packet’s source IP address and port.
Format is <address>:<port>
Destination IP Address
and Port
Packet’s destination IP address and port.
Format is <address>:<port>
Message
(continued)
Hit Count The aggregated number of messages received.
In MPHY Physical port number in which the packet arrived.
VLAN (int)
In Security Zone UUID (uuid)
Table C–1: Alert and IPS Block Log Formats (Continued)
Field Name Sub-Field Name Description
Zobrazit stránku 308
1 2 ... 304 305 306 307 308 309 310 311 312 313 314 ... 332 333

Komentáře k této Příručce

Žádné komentáře