Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Remediation
Administrator Help | TRITON AP-DATA | Version 8.3.x
Related topics:
To define the location of the syslog server and mail release gateway used for remediation:
1.
Select Settings > General > Remediation.
 
If you want incident data sent to the syslog, select Audit Incident > Send Syslog Message in the action plan for the policy.
Click Test Connection to send your syslog server a verification test message.
*
IP address or hostname - Enter the IP address or hostname for your mail release gateway.
*
Port - Enter the port number for your mail release gateway.
2.
Click OK to save your changes.
Syslog messages can be sent to a SIEM tool if desired. It is compatible with both ArcSight Common Event Format (CEF) and Audit Quality SIEM format.
The Arcsight CEF message includes the following information for each incident:
CEF:0|Forcepoint|TRITON AP-DATA|8.3|{id}|DLP Syslog|{severity}| act={action} duser={destinations} fname={attachments} msg={details} suser={source} cat={policyCategories} sourceServiceName={channel}analyzedBy={policyEngineName} loginName={name}sourceIp={ip}
where:
*
*
*
*
*
*
*
*
*
*
*
The Arcsight Audit Quality SIEM message adds additional information for each incident:
severityType=MEDIUM sourceHost=MNG_ENDPOINT_1 productVersion=8.3 maxMatches=6 timeStamp=2015-03-11 16:33:48.333 destinationHosts=ACCOUNTS.GOOGLE.COM,10.0.17.2 apVersion=8.3
where:
*
*
*
*
*
*
*
Incident risk ranking cases
When incident risk ranking cases are sent to syslog, the message includes case information. For example:
CEF:0|Forcepoint|TRITON AP-DATA|8.3.0.1184836|983645|DLP Syslog|1| riskScore=1.4 caseDescription=High-severity breach content and a suspected false-positive event caseDateAndTime=07 Jul. 2016, 9:33:18 AM caseClassification=Unknown caseSummary=Low risk content;Number of files in case (46);Destination is unusual;PII breach (1 match);Possible false positive (23%) numberOfIncidents=2 eventIDs=14359168827488891711,3765310750806591754
where:
*
*
*
*
*
*
*

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Copyright 2016 Forcepoint LLC. All rights reserved.