|Applies to Product:||USM Appliance™||AlienVault OSSIM®|
As part of your efforts to reduce the amount of events triggered by non-problematic, non-threat occurrences, you might want to create a policy to make sure that low-priority events don't trigger an alarm. For example, instant messaging programs such as Google Talk and Skype can potentially generate many events based on usage. This has the potential to create a good deal of "noise" in the USM Appliance system. It is generally unnecessary for USM Appliance to process these sorts of events unless a known vulnerability is associated with them. See also: Avoiding SQL Storage for Events - Video.
This process shows you how to discard any events of this type, using Google Talk as an example.
To filter Google Talk events by using a policy
Choose Configuration > Threat Intelligence > Policy.
On the Default Policy Group panel, click New.
Select the policy conditions: Source, Destination, Source Ports, and Destination Ports. Choose Any for all these policy conditions.
Click Insert New DS Group? in the event types tab, to match events related to Google Talk.
Write the DS Group Name and add events to the DS group by clicking Add by Data Source policy conditions.
Select AlienVault NIDS data source from the list.
Enable editing by clicking the pencil icon ()
Search for the ET Policy Gmail GTalk event and add it by clicking the plus (+) sign.
Click Submit Selection and then Update and close the Insert New DS Group window.
The new DS group appears in the policy conditions.
Deselect Any and select the newly created DS group.
Follow the instructions below to discard Google Talk-related events so that neither risk assessment, logical correlation, cross-correlation, nor SQL storage of events will be performed.
Note: Logging still occurs if the USM Appliance Logger is set to Yes in the Policy Consequences section.
To discard Google Talk-related events
- Open the SIEM tab in the policy consequences and select NO for SIEM.
- Enter a name for the policy rule and click UPDATE POLICY.
- Click Reload Policies.