- play_arrow What's New for Administrators
- play_arrow Overview of JSA Administration
- play_arrow User Management
- play_arrow License Management
- play_arrow System Management
- System Management
- System Health Information
- JSA Component Types
- Data Nodes
- Network Interface Management
- JSA System Time
- NAT-Enabled Networks
- Off-site Hosts Management
- Managed Hosts
- Configuration Changes in your JSA Environment
- Deploying Changes
- Restarting the Event Collection Service
- Shutting Down a System
- Restarting a System
- Collecting Log Files
- Changing the Root Password on Your JSA Console
- Resetting SIM
- play_arrow JSA Set Up Tasks
- JSA Set Up Tasks
- Network Hierarchy
- Automatic Updates
- Manual Updates
- Configuring System settings
- IF-MAP Server Certificates
- SSL Certificates
- IPv6 Addressing in JSA Deployments
- Advanced Iptables Rules Examples
- Data Retention
- System Notifications
- Custom Offense Close Reasons
- Configuring a Custom Asset Property
- Index Management
- Restrictions to Prevent Resource-intensive Searches
- App Hosts
- Checking the Integrity Of Event and Flow Logs
- Adding Custom Actions
- Managing Aggregated Data Views
- Accessing a GLOBALVIEW Database
- play_arrow Event Data Processing in JSA
- Event Data Processing in JSA
- DSM Editor Overview
- Properties in the DSM Editor
- Property Configuration in the DSM Editor
- Opening the DSM Editor
- Configuring a Log Source Type
- Configuring Property Autodetection for Log Source Types
- Configuring Log Source Autodetection for Log Source Types
- Configuring DSM Parameters for Log Source Types
- Custom Log Source Types
- Custom Property Definitions in the DSM Editor
- Event Mapping
- Exporting Contents from the DSM Editor
- play_arrow Using Reference Data in JSA
- play_arrow User Information Source Configuration
- play_arrow Juniper Networks X-Force Integration
- play_arrow Managing Authorized Services
- play_arrow Backup and Recovery
- play_arrow Flow Sources Management
- play_arrow Remote Networks and Services Configuration
- play_arrow Server Discovery
- play_arrow Domain Segmentation
- play_arrow Multitenant Management
- Multitenant Management
- User Roles in a Multitenant Environment
- Domains and Log Sources in Multitenant Environments
- Provisioning a New Tenant
- Monitoring License Usage in Multitenant Deployments
- Rules Management in Multitenant Deployments
- Network Hierarchy Updates in a Multitenant Deployment
- Retention Policies for Tenants
- play_arrow Asset Management
- play_arrow Configuring JSA to Forward Data to Other Systems
- Forward Data to Other Systems
- Adding Forwarding Destinations
- Configuring Forwarding Profiles
- Configuring Routing Rules to Forward Data
- Using Custom Rules and Rule Responses to Forward Data
- Configuring Routing Rules to Use the JSA Data Store
- Viewing Forwarding Destinations
- Viewing and Managing Forwarding Destinations
- Viewing and Managing Routing Rules
- play_arrow Event Store and Forward
- play_arrow Security Content
- play_arrow SNMP Trap Configuration
- play_arrow Protect Sensitive Data
- play_arrow Log Files
- play_arrow Common Ports and Servers Used by JSA
- play_arrow RESTful API
Flow
The flow category includes events that are related to flow actions.
The following table describes the low-level event categories and associated severity levels for the flow category.
Low-level event category | Category ID | Description | Severity level (0 - 10) |
---|---|---|---|
Unidirectional Flow | 14001 | Indicates a unidirectional flow of events. | 5 |
Low number of Unidirectional Flows | 14002 | Indicates a low number of unidirectional flows of events. | 5 |
Medium number of Unidirectional Flows | 14003 | Indicates a medium number of unidirectional flows of events. | 5 |
High number of Unidirectional Flows | 14004 | Indicates a high number of unidirectional flows of events. | 5 |
Unidirectional TCP Flow | 14005 | Indicates a unidirectional TCP flow. | 5 |
Low number of Unidirectional TCP Flows | 14006 | Indicates a low number of unidirectional TCP flows. | 5 |
Medium number of Unidirectional TCP Flows | 14007 | Indicates a medium number of unidirectional TCP flows. | 5 |
High number of Unidirectional TCP Flows | 14008 | Indicates a high number of unidirectional TCP flows. | 5 |
Unidirectional ICMP Flow | 14009 | Indicates a unidirectional ICMP flow. | 5 |
Low number of Unidirectional ICMP Flows | 14010 | Indicates a low number of unidirectional ICMP flows. | 5 |
Medium number of Unidirectional ICMP Flows | 14011 | Indicates a medium number of unidirectional ICMP flows. | 5 |
High number if Unidirectional ICMP Flows | 14012 | Indicates a high number of unidirectional ICMP flows. | 5 |
Suspicious ICMP Flow | 14013 | Indicates a suspicious ICMP flow. | 5 |
Suspicious UDP Flow | 14014 | Indicates a suspicious UDP flow. | 5 |
Suspicious TCP Flow | 14015 | Indicates a suspicious TCP flow. | 5 |
Suspicious Flow | 14016 | Indicates a suspicious flow. | 5 |
Empty Packet Flows | 14017 | Indicates empty packet flows. | 5 |
Low number of Empty Packet Flows | 14018 | Indicates a low number of empty packet flows. | 5 |
Medium number of Empty Packet Flows | 14019 | Indicates a medium number of empty packet flows. | 5 |
High number of Empty Packet Flows | 14020 | Indicates a high number of empty packet flows. | 5 |
Large Payload Flows | 14021 | Indicates a large payload of flows. | 5 |
Low number of Large Payload Flows | 14022 | Indicates a low number of large payload flows. | 5 |
Medium number of Large Payload Flows | 14023 | Indicates a medium number of large payload flows. | 5 |
High number of Large Payload Flows | 14024 | Indicates a high number of large payload flows. | 5 |
One Attacker to Many Target Flows | 14025 | Indicates that one attacker is targeting many flows. | 5 |
Many Attacker to one Target Flow | 14026 | Indicates that many attackers are targeting one flow. | 5 |
Unknown Flow | 14027 | Indicates an unknown flow. | 5 |
Netflow Record | 14028 | Indicates a Netflow record. | 5 |
Flow Record | 14029 | Indicates a Flow record. | 5 |
SFlow Record | 14030 | Indicates an SFlow record. | 5 |
Packeteer Record | 14031 | Indicates a Packeteer record. | 5 |
Misc Flow | 14032 | Indicates a misc flow. | 5 |
Large Data Transfer | 14033 | Indicates a large transfer of data. | 5 |
Large Data Transfer Outbound | 14034 | Indicates a large transfer of outbound data. | 5 |
VoIP Flows | 14035 | Indicates VoIP Flows. | 5 |