HP-UX Host Intrusion Detection System Version 4.3 administrator guide

Table Of Contents
5 Using the Schedule Manager Screen
This chapter describes how to configure HP-UX HIDS surveillance schedules, surveillance groups,
and detection templates. This chapter addresses the following topics:
“The Schedule Manager (page 57)
“Configuring Surveillance Schedules” (page 60)
“Configuring Surveillance Groups” (page 64)
“Configuring Detection Templates” (page 66)
“Setting Surveillance Schedule Timetables” (page 70)
“Configuring Alert Aggregation” (page 72)
“Configuring Monitor Failed Attempts” (page 75)
“Configuring Duplicate Alert Suppression” (page 76)
“Viewing Surveillance Schedule Details” (page 78)
“Predefined Surveillance Schedules and Groups” (page 80)
The Schedule Manager
The Schedule Manager screen helps you create and configure HP-UX HIDS surveillance schedules,
surveillance groups, and detection templates.
Using this screen, you can:
Add, rename, delete, and define surveillance schedules, including which surveillance groups
make up a schedule.
Add, rename, delete, and define surveillance groups, including which templates make up
a group, the days and times the group will be active, and the values for the properties of
the selected templates.
NOTE: A group’s timetable can be different in different schedules. A template’s property values
can be different in different groups
A surveillance schedule is what you activate on an agent host to monitor activities and report
alerts. It includes the name of one or more surveillance groups. A surveillance group consists of
one or more templates. A template consists of one or more properties. A property can have zero
or more values. The templates and their properties are predefined.
Surveillance schedules are saved in /etc/opt/ids/schedules/<schedname>.txt where
schedname is the name of the schedule. If you rename a schedule, its file is renamed. If you
save a schedule under a new name, the old file is renamed and the schedule is renamed. Saving
a schedule ensures that it has been written to disk.
Surveillance groups are saved in /etc/opt/ids/schedules/groups/<groupname>.txt
where groupname is the name of the group. If you rename a group, its file is renamed.
Schedules and groups are saved automatically when you first create them and every time you
exit from the System Manager screen. For information about the format and structure of
surveillance schedules and groups, see Appendix E (page 197).
The Schedule Manager screen comprises of four major parts:
The Configure tab, where you define surveillance schedules, groups, and template properties.
For more information, see “Configuring Surveillance Schedules” (page 60), “Configuring
Surveillance Groups” (page 64), and “Configuring Detection Templates” (page 66).
The Timetable tab, where you specify when each surveillance group of a surveillance
schedule will run. For more information, see “Setting Surveillance Schedule Timetables”
(page 70).
The Schedule Manager 57