You can monitor a simulation to determine if the results of the simulation changed. If a change occurs, then an event is generated. A maximum of 10 simulations can be in monitor mode.
When a simulation is in monitor mode, the defaults time range is 1 hour. This value overrides the configured time value when the simulation was created.
For information about event categories, see the Juniper Secure Analytics Users Guide.
- Click the Risks tab.
- On the navigation menu, select Simulation >Simulations.
- Select the simulation that you want to monitor.
- Click Monitor.
- In the Event Name field, type the name of the event you want to display on the Log Activity and Offenses tab.
- In the Event Description field, type a description for the event. The description is displayed in the Annotations of the event details.
- From the High-Level Category list, select the high-level event category that you want this simulation to use when processing events.
- From the Low-Level Category list, select the low-level event category that you want this simulation to use when processing events.
- Select the Ensure
the dispatched event is part of an offense check box if you
want, as a result of this monitored simulation, the events that are
forwarded to the Magistrate component. If no offense was generated,
then a new offense is created. If an offense exists, this event is
added to the existing offense. If you select the check box, then choose
one of the following options:
All events from a question are associated with a single offense.
A unique offense is created (or updated) for each unique asset.
- In the Additional
Actions section, select one or more of the following options:
Select this check box and specify the email address to send notifications if the event is generated. Use a comma to separate multiple email addresses.
Send to Syslog
Select this check box if you want to log the event.
For example, the syslog output might resemble:
Sep 28 12:39:01 localhost.localdomain ECS: Rule 'Name of Rule'Fired: 172.16.60.219:12642 -> 172.16.210.126:6666 6, Event Name:SCAN SYN FIN, QID: 1000398, Category: 1011, Notes: Eventdescription
Select this check box if you want events that generate as a result of this monitored question to display in the System Notifications item in the Dashboard.
- In the Enable Monitor section, select the check box to monitor the simulation.
- Click Save Monitor.