Dab tsi yog kev sib raug zoo hauv ArcSight?
Dab tsi yog kev sib raug zoo hauv ArcSight?

Video: Dab tsi yog kev sib raug zoo hauv ArcSight?

Video: Dab tsi yog kev sib raug zoo hauv ArcSight?
Video: yog hmoov dab tsi. Zoo Xyooj (cover) 2024, Kaum ib hlis
Anonim

Nyob zoo, Kev sib txheeb yog tus txheej txheem los taug qab kev sib raug zoo ntawm qhov xwm txheej raws li tau hais tseg hauv txoj cai. Thaum muaj cov xwm txheej tshwm sim uas phim cov xwm txheej tau teev tseg hauv txoj cai, cov xwm txheej uas ua rau muaj kev sib ntsib raug hu kev sib raug zoo xwm txheej.

Ib yam li ib tug yuav nug, dab tsi yog kev sib raug zoo thiab kev sib sau ua ke hauv ArcSight?

Kev sib txheeb yog tus txheej txheem los taug qab qhov kev sib raug zoo ntawm qhov xwm txheej raws li tau hais tseg. Thaum kev sib sau ua ke yog txheej txheem los sau cov xwm txheej zoo sib xws.

Tsis tas li, dab tsi yog qhov normalization hauv ArcSight? normalization yog tus txheej txheem ntawm kev noj qhov tseem ceeb uas muaj nyob rau hauv ib qho kev tshwm sim thiab qhia lawv mus rau hauv tus qauv schema. Cov ArcSight CEF hom ntawv muaj 400+ teb nyob rau hauv nws cov schema uas cov ntaub ntawv teev cia yuav mapped rau.

Dab tsi yog kev sib raug zoo hauv Siem?

Ntau yam khoom siv hauv koj lub network yuav tsum tau tsim cov ntawv teev kev tshwm sim uas tau pub rau koj SIEM qhov system. A SIEM correlation txoj cai qhia koj SIEM kab ke uas cov xwm txheej ntawm cov xwm txheej tuaj yeem yog qhov qhia txog kev tsis txaus ntseeg uas yuav qhia txog kev ruaj ntseg tsis muaj zog lossis kev tawm tsam cyber.

Dab tsi yog aggregation hauv Siem?

Kev sib sau ua ke yog cov txheej txheem ntawm kev txav cov ntaub ntawv thiab cov ntaub ntawv teev tseg los ntawm qhov chaw sib txawv rau hauv ib qho chaw khaws cia. Cov txheej txheem ntawm kev sib sau ua ke - suav nrog cov xwm txheej sib txawv no pub rau hauv ib qho chaw khaws cia - yog qhov tseem ceeb rau Kev Tswj Xyuas Kev Lag Luam thiab feem ntau SIEM platforms.

Pom zoo: