Up
Previous Next

Sheriff CSMâ„¢

Viewing Sheriff NIDS Events

You can view Sheriff NIDS events the same way as you do any other security events. For reference, see Security Events Views.

To view Sheriff NIDS events
  1. Go to Analysis > Security Events (SIEM) > SIEM.
  2. From the Data Sources list, select Sheriff NIDS.

    SIEM page that displays NIDS events.

    Sheriff NIDS events suggest that an attack may have occurred, but they don't guarantee that such attack has occurred. Therefore, you must examine the traffic that triggered the signature and validate the malicious intent, before proceeding with your investigation.

    At the bottom of the event details page, all Sheriff NIDS events include a payload and the rule that identified the issue. You can examine the payload of the offending packet, study the rule, or download the PCAP file for off-line analysis

This topic: Sheriff > UserGuides > SheriffCSMDocumentation > DeploymentGuide > IDSConfiguration > SheriffNIDS > ViewingSheriffNIDSEvents
Topic revision: 02 Feb 2022, SheriffCyberSecurity
Copyright 2020 Sheriff Cyber Security, LLC. All rights reserved.