Map LogRhythm alarm fields to security incident fields
You map individual alarm fields to the security incident fields. The preconfigured mapping can be edited, and color coding provided for the fields helps you monitor alarms you have already mapped. This step helps you visualize how your edits impact the fields on the security incident.
Antes de Iniciar
If you are unfamiliar with the LogRhythm alarms, navigate to the LogRhythm Client Console and review a few sample Alarm IDs. For the following example, LogRhythm alarms 9468 and 9474 were used to map the alarms to the security incident.
Por Que e Quando Desempenhar Esta Tarefa
The following figure shows the default mapping of alarms that is preconfigured for each alarm profile. This default mapping can be edited, and with this form, you customize the fields that populate the security incident. After you complete this mapping, you can see how adding or removing alarm fields potentially impacts the field values on the security incident.
On the left side of this form in the following figure, the LogRhythm alarm rules are outlined. The values of these alarm rules are mapped to the security incident fields on the right side of the form.
Procedimento
O que Fazer Depois
After you complete the field mapping, the next step is to Filter alarms for LogRhythm.