Eventtracker V7.1 Enterprise User Guide Description Updated in Accordance with Release Version 7.1 Build 20
Total Page:16
File Type:pdf, Size:1020Kb
EventTracker Enterprise User’s Guide Copyright All intellectual property rights in this work belong to Prism Microsystems, Inc. The information contained in this work must not be reproduced or distributed to others in any form or by any means, electronic or mechanical, for any purpose, without the prior permission of Prism Microsystems, Inc., or used except as expressly authorized in writing by Prism Microsystems, Inc. Copyright © 1999 - 2011 Prism Microsystems, Inc. All Rights Reserved. Trademarks All company, brand and product names are referenced for identification purposes only and may be trademarks or registered trademarks that are the sole property of their respective owners. Disclaimer Prism Microsystems, Inc. reserves the right to make changes to this manual and the equipment described herein without notice. Prism Microsystems, Inc. has made all reasonable efforts to ensure that the information in this manual is accurate and complete. However, Prism Microsystems, Inc. shall not be liable for any technical or editorial errors or omissions made herein or for incidental, special, or consequential damage of whatsoever nature resulting from the furnishing of this manual, or operation and performance of equipment in connection with this manual. EVENTTRACKER VER.7.1 ENTERPRISE USER GUIDE CONTENTS Contents About this Guide ................................................................................................................................xv Purpose of this guide ...................................................................................................................................... xv Who should read this guide ............................................................................................................................ xv Typographical Conventions ........................................................................................................................... xv Document Revision Control ........................................................................................................... xvi How to Get In Touch ..................................................................................................................... xvii Documentation Support ............................................................................................................................... xvii Customer Support ........................................................................................................................................ xvii Related Documents ........................................................................................................................ xvii Chapter 1 Getting Started .................................................................................................................19 About EventTracker ..........................................................................................................................20 EventTracker Services and Ports ......................................................................................................20 Starting EventTracker .......................................................................................................................23 Event-O-Meter ..................................................................................................................................30 Incorporating Your Company Logo ..................................................................................................31 EventTracker Components................................................................................................................32 System Manager ............................................................................................................................................. 32 EventVault Manager ...................................................................................................................................... 33 Events Knowledge Base ................................................................................................................................. 35 EventTracker Diagnostic & Support Tool ...................................................................................................... 35 Setting Debug Levels ..................................................................................................................................... 38 Obfuscating Classified Information................................................................................................................ 40 Diagnostic Alert ................................................................................................................................43 Replacing Outdated CRL ..................................................................................................................45 Updating EventTracker Users List ....................................................................................................48 Exiting EventTracker ........................................................................................................................50 Chapter 2 Analyzing Alerts ...............................................................................................................54 Alerts Summary ................................................................................................................................55 Tuning Alerts Configuration .......................................................................................................................... 60 Web Slices ........................................................................................................................................61 Adding Web Slices to the Favorites Bar ........................................................................................................ 61 Chapter 3 Analyzing Enterprise Activities ......................................................................................63 Monitoring Enterprise Activities ......................................................................................................64 Enterprise Activity Dashlets ........................................................................................................................... 64 Viewing Security Dashboard ............................................................................................................65 Configuring Category Dashlets ...................................................................................................................... 67 Customizing Security Dashboard ................................................................................................................... 71 Resetting Personalization ............................................................................................................................... 73 iii EVENTTRACKER VER.7.1 ENTERPRISE USER GUIDE CONTENTS Adding Behavior Dashlets ................................................................................................................73 Analyzing non-Admin User Activities .............................................................................................75 Analyzing Admin User Activities .....................................................................................................79 Analyzing Activities per System ......................................................................................................80 Analyzing IP Addresses by Traffic ...................................................................................................81 Analyzing Processes by Occurrence .................................................................................................85 Analyzing Events by Occurrences ....................................................................................................88 Analyzing Log on Failure Activity ...................................................................................................88 Analyzing Runaway Process Activity ...............................................................................................89 Analyzing Software Activity ............................................................................................................90 Analyzing Network Activity .............................................................................................................91 Analyzing Application Activity ........................................................................................................92 Monitoring USB Activity .................................................................................................................93 Analyzing USB Activity ................................................................................................................................ 94 Configuring Behavior Filters ............................................................................................................94 Analyzing Volume ............................................................................................................................97 Enterprise Activity Behavior Settings.............................................................................................100 Behavior Rules ................................................................................................................................102 Managing Behavior Rules ...........................................................................................................................