Event Management Flashcards
1
Q
Interface monitoring
A
- Up or down
- The most important statistic
- No special rights or permissions required
- Green is good, red is bad
- Alarming and alerting
- Notification should an interface fail to report
- Email, SMS
- Short-term and long-term reporting
- View availability over time
- Not focused on additional details
- Additional monitoring may require SNMP
2
Q
SIEM
A
- Security Information and Event Management
- Security events and information
- Security alerts
- Real-time information
- Log aggregation and long-term storage
- Usually includes advanced reporting features
- Data correlation
- Link diverse data types
- Forensic analysis
- Gather details after an event
3
Q
SNMP
A
• Simple Network Management Protocol
• A database of data (MIB) - Management Information
Base
- SNMP v1 - The original
- Structured tables, in-the-clear
• SNMP v2 – A good step ahead
• Data type enhancements, bulk transfers, still in-the-
clear
- SNMP v3 - The new standard
- Message integrity, authentication, encryption
- SNMP information can be very detailed
- Access should be very limited
4
Q
Syslog
A
- Standard for message logging
- Diverse systems, consolidated log
- Usually a central logging receiver
- Integrated into the SIEM
• You’re going to need a lot of disk space