Network Monitoring Flashcards
Simple Network Management Protocol (SNMP)
Sends and receives data from managed devices back to a centralized network management station
Granular (SNPM)
Sent trap messages get a unique objective identifier to distinguish each message as a unique message
Management Information Base (MIB)
The structure of the management data of a device subsystem using a hierarchical namespace containing object identifiers
Verbose
SNMP traps may be configured to contain all the information about a given alert or event as a payload
SNMP Trap
SNMP PDU an unrequested message an agent can send the MIB to notify about an important event
System Logging Protocol (Syslog)
Sends system log or event messages to a central syslog server
Audit Log / Audit Trail
Contains a sequence of events for a particular activity
Application Log (Windows)
Contains information about software running on a client or server
Security Log (Windows)
Contains information about the security of a client or server
System Log (Windows)
Contains information about the OS itself
Windows Logs entry levels
Informational
Warning
Error
Security Information and Event Management (SIEM)
Provides real-time or near-real-time analysis of security alerts generated by network hardware or applications
Security Information and Event Management (SIEM) Log Collection
*Provides important forensic tools
*Helps address compliance reporting requirements
Security Information and Event Management (SIEM)
Normalization
*Nomalize data into a common model
*Maps log messages into a common data model,
*Connect and analyze related events
Security Information and Event Management (SIEM)
Correlation
Links the logs and events from different systems or applications into a single data feed