サポートと今すぐチャット
サポートとのチャット

Change Auditor Threat Detection 7.0.3 - Deployment Guide

Configured server deployment details

For a configured server, the following deployment details are displayed:

Removing a configuration

Deleting the configuration only removes configuration information from Change Auditor. It does not remove data or configuration on the Threat Detection server.

If you are removing the configuration as a part of a clean up process, you can delete the Threat Detection server after removing configuration.

If you are removing the configuration and plan to start over, you can either revert to a snapshot from a previously deployed (but not configured) Threat Detection server or deploy a new Threat Detection server.

 

1
Select Administration Tasks | Configuration | Threat Detection.
2
Click Remove Configuration.

Historical events and your baseline calculations

Before the Threat Detection server can generate alerts, it needs to establish user behavior baseline. The baseline is built by processing 30 days of historical or real time events. Refer to the Change Auditor Threat Detection User Guide for information about baseline modeling.

When you create the Threat Detection configuration, you can specify how many days of historical events should be sent to the Threat Detection server to create the baseline.

Real-time events (0 days)

Historical events (more than 0 days)

Use the following as guidance on the number of days to specify when you create your Threat Detection configuration:

Threat Detection configuration commands

 

 

 

関連ドキュメント

The document was helpful.

評価を選択

I easily found the information I needed.

評価を選択