HP-UX Host Intrusion Detection System Version 4.7 Administrator Guide HP-UX 11i v3 (766144-001, March 2014)
4 Using the System Manager Screen..............................................................38
Starting the HP-UX HIDS System Manager..................................................................................39
Stopping the HP-UX HIDS System Manager................................................................................39
System Manager Components..................................................................................................40
Starting HP-UX HIDS Agents.....................................................................................................41
Getting the Status of Agent Hosts..............................................................................................42
Resynchronizing Agent Hosts....................................................................................................43
Activating Schedules on Agent Hosts.........................................................................................44
Stopping Schedules on Agent Hosts..........................................................................................44
Halting HP-UX HIDS Agents.....................................................................................................45
Accessing Other Screens.........................................................................................................46
Schedule Manager Screen..................................................................................................46
Host Manager Screen.........................................................................................................46
Network Node Screen........................................................................................................46
Preferences Screen.............................................................................................................46
Returning to the System Manager Screen...............................................................................47
5 Using the Schedule Manager Screen..........................................................48
The Schedule Manager...........................................................................................................48
Creating a Surveillance Schedule.........................................................................................49
Opening the Schedule Manager Screen...............................................................................49
Closing the Schedule Manager Screen.................................................................................50
Configuring Surveillance Schedules...........................................................................................50
Creating a New Surveillance Schedule.................................................................................51
Copying a Surveillance Schedule.........................................................................................51
Modifying a Surveillance Schedule......................................................................................52
Renaming a Surveillance Schedule.......................................................................................52
Deleting a Surveillance Schedule.........................................................................................52
Undoing and Redoing Changes...........................................................................................53
Saving a Surveillance Schedule...........................................................................................53
Configuring to Monitor HP-UX Containers (HP-UX SRP).................................................................53
Adding a New Container (SRP) Configuration.......................................................................53
Copying a Container (SRP) Configuration..............................................................................54
Modifying a Container (SRP) Configuration...........................................................................55
Renaming a Container (SRP) Configuration............................................................................55
Deleting a Container (SRP) Configuration..............................................................................55
Configuring Surveillance Groups..............................................................................................55
Creating a New Surveillance Group.....................................................................................56
Copying a Surveillance Group.............................................................................................56
Modifying a Surveillance Group..........................................................................................57
Renaming a Surveillance Group...........................................................................................57
Deleting a Surveillance Group.............................................................................................58
Undoing and Redoing Changes...........................................................................................58
Saving a Surveillance Group...............................................................................................58
Configuring Detection Templates...............................................................................................58
Modifying a Property Value in a Template.............................................................................59
Undoing and Redoing Changes...........................................................................................61
Suggested Best Practices.....................................................................................................61
Some Template Configuration Guidelines..............................................................................61
Setting Surveillance Schedule Timetables...................................................................................62
Specifying When a Schedule Will Run..................................................................................62
Canceling Changes...........................................................................................................64
Saving a Surveillance Schedule...........................................................................................64
Configuring Alert Aggregation.................................................................................................64
Guidelines for Configuring Alert Aggregation .......................................................................66
4 Contents