Getting Started with ESM Flashcards
Why you need to do rule updates on your SIEM?
This is because Trellix team is always developing new signatures to identify threats on network traffic
After you do a rule update on your SIEM you need to do a Rollout. How can you do this?
- Clic on Policy editor
- Clic on Operations
- Clic on Rollout
- Check Rollout policy to all devices now
- Clic OK
Trellix ESM allows you to configure which two types of user accounts?
- System Administrators
- General Users
To what refers the process of Keying on ESM?
It is the process to exchange ssh keys between devices when adding devices like ACE, ERC, ELM and so on to the ESM. This procedure allows to protect comunication between each device.
What is the “tail -f /var/log/message” command useful when working with Trellix components directly from the shell?
It allows to observe the current activity on the device.
What you need to do after an update process on any of the Trellix components?
- You need to key the device again
- Write out device data sources
- Rollout policies to all devices
Yo have been asked to do a write out of the devices data sources on your SIEM. How can you do this?
This is applied on ERC you go to Data Sources, and then uncheck and check again any data source that has the Parsing option enabled, this enables the Write button on the bottom of the window.
What is aggregation concept refers to on ESM?
Is the ability to group multiple events on a single event with a event count.