How to get a connection out of the FireSight matrix?

Hi all

someone had a useful suggest how can I get a matrix of useful connection on FireSight management to create a Ruleset for the SAA, which is now on allow all... Should be a list of IP source and destination with the port and maybe a counter - did an investigation into the events of connection - but it's too much information and too many events - and I only events of the last 2 days... I would like to get the result one or two weeks - there may be a way to do this?

Thanks in advance

Helmut

You can generate reports based on the events of connection and connection workflows.  You can create a workflow custom with something as initiator IP, voicemail, IP, dst port, County.  This would give you the number of connections between an IP src/dst on a given DST port.

Regarding the history of connection that is a difficult question according to the volume of traffic passing through your device.  The default connection limit is 1 M connections.  You can raise as part of the political system's database, but be careful because it hit too high can cause it takes a long time to process requests for connection events.  A week is really all we can always hope and even what is often too long (too many connections).

Tags: Cisco Security

Similar Questions

  • I get my email on two computers. How to make a computer out of the loop?

    I get my email on two computers. How to make a computer out of the loop without jeopardizing my Comcast email account?

    Using Outlook Express? Go to: tools | Accounts and delete the account. If you think you can it in the future, go to the properties of the account, and under the general tab, simply uncheck: include this account when receiving or synchronization.

    If you are interested, you can receive messages at a time without losing them on one.

    On both machines:

    Tools | Accounts | Mail | Properties | Advanced - Check: leave a copy of messages on the server.

    On a single computer only, make sure to delete messages after X days to satisfy your allocated space that you get from your server.

  • How to get back my data for the health and the watch Apps once I've restored my phone?

    How to get back my data for the health and the watch Apps once I've restored my phone?

    From the backup, you're going to be restoration.

    If you back up to iTunes, make sure that it is an encrypted backup.

  • Try to play a movie but I have WMP cannot play the file how to get to play or delete the Xvid codec to play?

    How to get to play or delete the Xvid codec to play? Movies in AVI format, I converted it to WMP, but he won't play again

    No guarantee but maybe you need the XviD Codec.

    (FWIW... it's always a good idea to create a system)
    Restore point before installing software or updates)

    XviD Codec
    http://www.xvidmovies.com/codec/

  • How to get distinct records by using the ListAgg OBIEE report function?

    Hi all

    I get a correct result as mentioned below. But I don't see duplicates in my result here, in my example, I get duplicate for the name of the employee 'Pat '. So how to get Distinct values by using the LISTAGG function?

    Data set of sample with the Department and its employees

    Service employee

    ----------      ----------

    Marketing Michael

    Pat of marketing

    Pat of marketing

    Pat of marketing

    Purchase of Den

    Purchase of Alexander

    Purchase of Shelli

    Purchase of Sigal

    Guy of purchase

    Purchase of Karen

    Using the ListAgg function, we can convert it to:

    Employees of the Department

    -----------     -------------------------------------

    Marketing of Pat, Pat, Pat, Michael

    Purchase of Sigal, Shelli, Karen, Guy, Den, Alexander

    I tried a lot of things, but I'm not able to understand how exactly this can be achieved, if anyone has any idea or suggestions please do share, thanks in advance.

    After much research, I found the solution & I want to share what he finds very useful, we can create SQL logic in the Advanced tab, as below and after you click Rescan, and then you will get your desired results.

    SELECT saw_0, Evaluate_Aggr T1.dept ("ListAgg(%1,'' & '') intra group (about 1%)") ("as long as VarChar (1000), T1.emp) saw_1 FROM)

    SELECT 'emp_dept '. "the Department dept,

    'emp_dept '. "' employee ' emp

    IN THE "DOMAIN".

    GROUP BY dept, emp

    ) T1 GROUP FROM T1.dept ORDER BY saw_0

    Also note here that we have good anti-aliasing for columns parent (ex: saw_0, saw_1), another by mistake oracle bi server.

  • How to get Camera Raw to recognize the new Nikon D500 camera raw files?

    How to get Camera Raw to recognize the new Nikon D500 camera raw files?

    Devices supported by Adobe Camera Raw

    The D500 has been supported since camera 9.5 Raw which is only compatible with versions of Photoshop CS6 and Cloud.

    What version of Photoshop are you running?

  • How to get audio to play on the timeline by rubbing through

    How to get audio to play on the timeline during the treatment, the clip is not cut, clip does not display an audio wave, looked through the help did not answer. When the clip is imported without options rise so uncertain where the issue is, any help is greatly appreciated, ty

    There is an option in the Preferences / Audio: audio playback while rubbing.

  • Have on current PC, Win 7 64 bit CS5; How to get *.exe to transfer to the new computer after removal of old

    Have on current PC, Win 7 64 bit CS5; How to get *.exe to transfer to the new computer after removal of old?

    https://helpx.Adobe.com/Creative-Suite/KB/CS5-product-downloads.html

  • How can getting error Code U44M1P7 during the upgrade, I fix?

    How can getting error Code U44M1P7 during the upgrade, I fix?

    Update product that you are trying to install?

    Is it compared to the creative or perpetual clouds?

    Please check following if you have creative clouds.

    http://helpx.Adobe.com/Creative-Suite/KB/error-u44m1p7-installing-updates-CCM.html

  • How to get a chart deleted in the library of CC?

    I was project work in! Adobe Photoshop CC 2015 which has many layers, I recorded in the form of a chart in a CC library.

    I noticed that dynamic objects are all connected to the CC service now. I'm a little confused by the latter, but basically what happened was I deleted the image of the CC library and I noticed the smart object I is now a broken link, and I no longer one of my diapers.

    Screen Shot 2015-07-14 at 4.38.29 AM.png

    He just wants me to re-edit the link to the .psb file and I can not locate the .psb on my macintosh or an archive on the Web site. Also, I don't find a way to remove a dynamic object to retrieve my diapers. If anyone knows how to get my back layers it is all I care, I think I have lost so much work.

    Screen Shot 2015-07-14 at 4.39.49 AM.png

    I never knew that remove the chart would break the link to keep as an object dynamic with base and not just release the layers.

    I solved the problem was looking around and looking for my records/mac to find the file. Finally, after an hour or two, I decided that I could not find a way to recover my layers in photoshop. I decided to test a smart object and to try and find where they are stored to. I have made a simple chart and then dragged back out is a dynamic object CC, then recorded on and he showed me where it was saved previously (temporarily).

    I have just named the Psd as FIND ME and made the Spotlight search on my mac but I couldn't find it again because the files are located in a hidden folder. the road was private > var > folders > MMOS > m6vt8w147zwsp8mvf2pm0000gn > T > TemporaryItems - I don't know if this changes all the time and I think it will be different for windows users.

    So after I saved the file in the same location as the file that I lost (so I guess because of the names of files), I was now able to open this file, so I opened the file and somewhere a broken link, but fortunately I opened one that had all my layers inside and immediately outside registered as a new psd document. I think I could get it back because I had not closed the document and its possible it could work only on macintosh computers.

    I don't really think I like this new thing of linked smart objects CC it seems slower and, of course, can easily be broken and lost without a backup, I used this method for a while now, and every time that I dragged a chart, he simply created a dynamic object that is more safe and never had a problem with a broken link. I'm going to keep backups and generally do all this didn't expect since this is a new feature. Sorry and good luck if you have a similar problem. I suggest you do what I did, do not know another way to fix once its broken and you have back ups.

  • How to get IP/MAC information of the governing body ILO as stated in the material status tab

    Hello

    I know there are scripts of HP to collect information of the IPC/MAC (hpconfg get_network.xml) ILO Governing Council and then use VMware powercli IPMI script to feed DPM.

    as published on http://www.vpeeling.com/?tag=scripting

    Add-PSSnapin vmware. VimAutomation.core - ErrorAction SilentlyContinue

    SE connect-VIserver-Server your.vcenter.server

    $VMHosts = @(import-Csv "C:\scripts\host-info.csv")

    $IPMIUser = "dpmuser".
    $IPMIPass = "dpmpass".

    {foreach ($VMhost to $VMHosts)

    $esxMoRef = get-vmhost $VMHost.Hostname | % {Get-view $_.} ID}
    $IpmiInfo = new-Object Vmware.Vim.HostIpmiInfo
    $IpmiInfo.BmcIpAddress = $VMHost.iLOIP
    $IpmiInfo.BmcMacAddress = $VMHost.iLOMAC
    $IpmiInfo.Login = $IPMIUser
    $IpmiInfo.Password = $IPMIPass
    $esxMoRef.UpdateIpmi ($IpmiInfo)

    }

    But, the question I got recently. How can get out us of this info via vCenter? The vClient has the named material status tab and we see this info.

    hw_status.PNG

    Did anyone tried it this way?

    PowerCLI or SDK (c#), his is not serious.

    Thanks in advance

    A.S.

    You may have gotten a solution now...

    In any case, I found this function (Get-VMHostWSManInstance) which works fine:

    http://blogs.VMware.com/vipowershell/2009/03/monitoring-ESX-hardware-with-PowerShell.html

    The most difficult part is to identify the CIM class containing the BMC MAC/IP address (in my case I need just an IP address). After digging in this doc:

    http://www.VMware.com/support/developer/CIM-SDK/smash/U3/GA/apirefdoc/OMC_IPMIIPProtocolEndpoint.html

    I had the chance to locate: OMC_IPMIIPProtocolEndpoint

    The Get-VMHostWSManInstance call:

    Get-VMHostWSManInstance - VMHost (get-vmhost 'vmhost1') - OMC_IPMIIPProtocolEndpoint - ignoreCertFailures of the class | Select IPv4Address, MACAddress

    will give the address IP/MAC of BMC.

    BTW, I'm using PowerCLI 5.0.1 on Windows 7, is the host ESX 4.x

  • How to get two laptops to access the wireless network.

    My chip wireless on a Dell Inspiron 1520 laptop (intel pro wireless 3954bg) can find the wireless network if I use Intel Pro software, but Windows cannot find the wireless network. My real growth problem trying to connect a second computer; an IBM T42 think Pad computer to the wireless network, but I get a message that the network is secure, and the second computer keeps trying to acquire an address, but will not acquire an address. He just continues to try to acquire again and again, he can never acquire it. This second computer using Windows to configure the Wi - Fi connection and was working fine until I tried to connect the Dell laptop upward. Then, the IBM laptop cannot acquire an address. I go around and try to understand it. Someone at - it information to solve this problem? Both computers are runing Windows XP Pro SP3. My wireless router is a Belkin54g (F5D7230-4V8000)

    Thanks for any help,

    Btk (billy the kid)

    You can control a with either wireless network adapter software integrated in Windows XP (or WZC Wireless Zero Configuration) or with software provided by the manufacturer of the card (for example, Intel PROSet/Wireless), but not both at the same time.

    Most, but not all, software configuration wireless no Windows is smart enough to disable WZC automatically.

    There are a few sites that offer "safety tips" for wireless networks which includes 'hide' your wireless network by disabling the SSID broadcast.  This is not a good idea and does not, in fact, your wireless security.  See http://blogs.technet.com/b/steriley/archive/2007/10/16/myth-vs-reality-wireless-ssids.aspx if you have disabled broadcast SSID of your router, automatic configuration won't be able to find it.

    I get a message that the network is secure, and the second computer guard trying to acquire an address, but will not acquire an address

    If you have enabled encryption wireless router (a very good idea), you will need to enter the correct password in order to connect a find an IP address. What type of wireless encryption configured on the router?

    This second computer using Windows to configure the Wi - Fi connection and was working fine until I tried to connect the Dell laptop upward. Then the IBM laptop cannot acquire an address.

    You have changed something else.  The idea of a wireless network is to allow multiple computers to connect; connection to a computer shouldn't affect how another computer connects.

    The easiest way is to configure your router to connect a computer using an Ethernet cable (if you connect wireless, you will be disconnected when you make a change to the configuration of the router wireless).  For the Belkin router User Guide is here--> http://cache-www.belkin.com/support/dl/p74559-f_f5d7230-4v8xxx_manual.pdf

    Open a web browser (Internet Explorer, Firefox, etc.) and type 192.168.2.1 in the address box.  You should get to the home page of the router. Click on the "Login" link at the top.  The default password for the router is blank (no password) unless you changed it.

    Click on the link "Channel and SSID" under the heading "wireless" on the left side of the page.

    • Make sure that there is to check the "Broadcast SSID"
    • "Wireless mode" should be "g only" or "fashion g and b" (the latter is necessary only if you have a very old b wireless adapter in one of your computers)
    • I suggest you let off QoS (but click on "more info" or see what says the User Guide)
    • The wireless channel should be 1, 6 or 11.  If you have no difficulties, let him you will find
    • "Protected mode" should be off (but click on "more info" or see what says the User Guide)
    • If you make changes, click on "Apply Changes".

    Click on the 'Security' line under the heading "wireless".  You should be able to see both what type (if any) encryption is configured (64-bit WEP, 128-bit WEP, WPA, or WPA2) and the password (if any).  Unless your computer maps are old, you should use WPA2.  If the adapter in one or more of your computers is too old to be capable of WPA2, use WPA.  Regardless of the bit, WEP length, is easily broken.

  • How to get wifi connection after reinstalling factory default DVD for Iconia W3-810?

    My W3-810 Iconia has been reset using Acer Recovery DVD. After that 8 window has been restarted, he not been able to find the wireless device.

    Does anyone know how to get a wifi connection after reinstalling factory default DVD?

    Best is to download the drivers for a different machine, then transfer to the W3 with a USB or SD card. Once they are installed included you be back running.

  • How to get rid three point on the Brush tool numbers?

    Help!.png

    How do you get the ride of these numbers on my brush tool, I have allowed them on accident and now I can't get rid of them!

    They are markers of tool color sampling. Choose the color sampler tool

    and in the Options bar, click here

    Also:

    Once you have selected the color sampler tool, you can simply drag each marker out of the picture.

  • How to get sqlplus not to use the output of size documents fixed?

    I want to generate the sql code to clear all data in tables in the database of flat files, one file per table, one row per record.  I thought I'd try to use the ascii code for characters inherited 31 as a delimiter to separate the fields and start sqlplus. But a problem is how do you get to specify linesize? Are there not a way to get out of creating fixed size records in sqlplus? I would prefer each line to just be so great that it must be rather than set the linesize being the absolute maximum. (32767) or understand what the maximum size is on a per-table basis.

    Is it possible to do?

    What I've tried so far (so I would have executed him each resulting sort script d30_x.) OK but how to get rid of this thing linesize?

    / * create dump file using US 31 to separate the fields * /.

    wrap off Set

    Set linesize

    Set feedback off

    set pagesize 0

    set verify off

    UNDEF tab;

    set myfile = d30_ & & tab... SQL;

    is prompt myfile and myfile;

    coil & myfile

    Guest set linesize 2500

    Guest set pagesize 0

    Guest departed wrap

    quick game check out

    Quick spool & tab... LST

    Select guest of

    Select lower (column_name) |' | Chr (31)

    ||'
    of user_tab_columns
    where table_name = upper ('& tab') and
    column_id! = (select max (column_id) in the user_tab_columns where)
    table_name = upper ('& tab'))
    order of column_id
    /
    Select lower (column_name)
    of user_tab_columns
    where table_name = upper ('& tab') and
    column_id = (select max (column_id) in the user_tab_columns where)
    table_name = upper ('& tab'))
    order of column_id
    /
    from guest & tab
    Guest /.

    prompt off spool
    spool off

    Wait, I think it works!  Tell him to use the maximum linesize, then

    tell him to get rid of these spaces.

    OOPS I forgot something. A problem with this is that if there are embedded newlines \r \n one of those or both in a field, then this format that uses the newline to indicate the end of the recording is toast. And I know that they are inclined to do this. (Users can not live with them, can't live without 'em). More on that later.

    / * create dump file using US 31 to separate the fields * /.
    wrap off Set
    Set feedback off

    set linesize 150
    set pagesize 0
    set verify off

    UNDEF tab;

    set myfile = d30_ & tab... SQL;
    prompt myfile is &myfile;

    coil & myfile
    Guest set pagesize 0
    Guest departed wrap
    quick game check out
    prompt value trimspool on
    Guest trimout value on
    Guest set linesize 32767
    fast coil & tab... LST

    Select guest of
    Select lower (column_name) |' | Chr (31) | »
    of user_tab_columns
    where table_name = upper ('& tab') and
    column_id! = (select max (column_id) in the user_tab_columns where)
    table_name = upper ('& tab'))
    order of column_id
    /
    Select lower (column_name)
    of user_tab_columns
    where table_name = upper ('& tab') and
    column_id = (select max (column_id) in the user_tab_columns where)
    table_name = upper ('& tab'))
    order of column_id
    /
    Guest of & tab
    Guest /.

    prompt off spool
    spool off

    Post edited by: Lake

Maybe you are looking for