Create alarms that meet Unified Capabilities Approved Products List (UCAPL) requirements.
Create an Internal Event Match alarm matching on Signature ID for specific triggers:
When multiple failed logons for the same user reach an adjustable threshold, set the value to
306-36.When a user account is locked due to reaching the no activity threshold, set the value to
306-35.If a user tries to log on to the system after reaching the number of allowed concurrent sessions, set the value to
306-37.When a system file integrity check fails, set the value to
306-50085.When common access card (CAC) or web server certificates are about to expire set the value to
306-50081,306-50082,306-50083, or306-50084.Note
The alarm triggers 60 days before the certificate expires, then on a weekly basis. You cannot change the number of days.
Configure an SNMP trap so that the alarm sends a trap to the NMS when it detects that the system is no longer operating in an approved or secure state.
Create an alarm matching on any condition, then click → .
Click → , select the recipient, then click OK.
Click → → → .
Select SNMP Template for Type field and enter the text for the message, then click OK.
On the Template Management page, select the new template and click OK.
Complete the remaining alarm settings.
Configure a syslog message so that the alarm sends a syslog message to NMS when it detects that the system is no longer operating in an approved or secure state.
Create an alarm matching on any condition, then click → .
Click → , select the recipient and click OK.
In the Send Message field, click → → .
Select Syslog Template for Type field and enter the text for the message, then click OK.
On the Template Management page, select the new template, then click OK.
Complete the remaining alarm settings.
Configure an SNMP trap so that the alarm notifies the appropriate Network Operations Center (NOC) in 30 seconds if a security log fails to record required events.
Select → → or → → .
Select the Security Log Failure Trap to configure one or more profiles for the traps to be sent to, then click Apply.
Trellix ESM sends SNMP traps to the SNMP profile recipient with the message Failed to write to the security log.
Configure an SNMP trap so that the alarm notifies when the audit functions (such as the database, cpservice, IPSDBServer) start or shut down.
Select SNMP traps or SNMP Settings and click Database Up/Down Traps.
Configure one or more profiles for the traps to be sent to and click Apply.
Trigger an alarm when an administrative session exists for each of the defined administrative roles.
Create an Internal Event Match alarm matching on Signature ID.
Enter the Values for:
Audit Administrator -
306–38Crypto-Administrator -
306–39Power User -
306–40