- play_arrow JSA Risk Manager
- play_arrow JSA Risk Manager configuration
- play_arrow Network Device Management
- play_arrow Network Device Management
- Device Discovery Process
- Discovering Devices in your Network
- Importing Multiple Devices from a CSV File
- Adding a Network Device to JSA Risk Manager
- Deleting a Device from JSA Risk Manager
- Finding Network Devices in the Device List
- Adding Device Information to the Topology
- Collecting Neighbor Data to Update the Topology
- Configuring the Discovery Schedule to Populate Device Information
- play_arrow Device Configuration Backup Jobs
- play_arrow Network Connections Overview
- play_arrow Network Connections Overview
- play_arrow Network Device Configuration and Monitoring
- play_arrow Network Device Configuration and Monitoring
- Searching Device Rules
- Filtering Device Rules by User or Group
- Comparing the Configuration of your Network Devices
- Adding or Deleting a Device in JSA Risk Manager
- Backing up a Device to get its Configuration Data
- Discovering Devices in your Network
- play_arrow Log Source Mapping in JSA
- play_arrow Protocol Configuration for Network Devices
- play_arrow Schedules for Discovery and Backup
- play_arrow Firewall Rule Event Counts of Check Point Devices
- play_arrow Network Topology
- play_arrow Network Topology
- play_arrow CIS Benchmark Scans
- play_arrow Network Simulations in JSA Risk Manager
- play_arrow Network Simulations in JSA Risk Manager
- Simulation Tests
- Creating a Simulation
- Duplicating a Simulation
- Manually Running a Simulation
- play_arrow Network Configuration Change Simulation
- Simulating an Attack on an SSH Protocol
- Viewing Simulation Results
- Approving Simulation Results
- Revoking a Simulation Approval
- Assigning Simulations to Group for Tracking
- play_arrow Topology models
- play_arrow Reports
- play_arrow Audit Log Data
Asset Question Results
SUMMARY Asset results display after you submit a Policy Monitor question. The Risk Score indicates the level of risk that is associated with the question.
The Risk Score calculation is based on the importance factor that is assigned to the question, and the number of results returned for the question.
The following table describes the parameters for asset results:
Parameter | Description |
---|---|
IP | The IP address of the asset. |
Name | The name of the asset, as obtained from the asset profile. For more information about asset profiles, see the Juniper Secure Analytics Users Guide. |
VLAN | The name of the VLAN associated with the asset. |
Weight | The weight of the asset, as obtained from the asset profile. |
Destination Port(s) | The list of destination ports associated with this asset, in context of the question tests. If multiple ports are associated with this asset and question, this field indicates Multiple and the number of multiple ports. The list of ports is obtained by filtering the connections that are associated with this question to obtain all unique ports where the asset was either the source, destination, or the connection. Click Multiple (N) to view the connections. This display provides the aggregated connections by port, which is filtered by the asset IP address, and based on the time interval specified in the question. |
Protocol(s) | The list of protocols associated with this asset, in context of the question tests. If multiple protocols are associated with this asset and question, this field indicates Multiple and the number of protocols. The list of protocols is obtained by filtering the connections that are associated with this question to obtain all unique protocols where the asset was either the source, destination, or the connection. Click Multiple (N) to view the Connections. This display provides the aggregated connections by protocol, which is filtered by the asset IP address, and based on the time interval specified in the question. |
Flow App(s) | The list of applications associated with this asset, in context of the question tests. If multiple applications are associated with this asset and question, this field indicates Multiple and the number of applications. The list of applications is obtained by filtering the connections that are associated with this question to obtain all unique applications where the asset was either the source, destination, or the connection. Click Multiple (N) to view the Connections. This display provides the aggregated connections by application, which is filtered by the asset IP address, and based on the time interval specified in the question. |
Vuln(s) | The list of vulnerabilities associated with this asset, in context of the question tests. If multiple vulnerabilities are associated with this asset and question, this field indicates Multiple and the number of vulnerabilities. The list of vulnerabilities is obtained using a list of all vulnerabilities that are compiled from relevant tests and using this list to filter the vulnerabilities detected on this asset. If no vulnerabilities are specified for this question, then all vulnerabilities on the asset are used to compile this list. Click Multiple (N) to view the Assets. This display provides the aggregated connections by vulnerability, which is filtered by the asset IP address, and based on the time interval specified in the question. |
Flow Count | The total flow count associated with this asset, in context of the question tests. The flow count is determined by filtering the connections that are associated with this question to obtain the flow count total, where asset was either the source, destination, or the connection. |
Source(s) | The list of source IP addresses associated with this asset, in context of the question tests. If multiple source IP addresses are associated with this asset and question, this field indicates Multiple and the number of source IP addresses. The list of source IP addresses is obtained by filtering the connections that are associated with this question. The obtained list contains all unique source IP addresses where the asset is the destination of the connection. Click Multiple (N) to view the Connections. This display provides the aggregated connections by source IP address, which is filtered by the asset IP address based on the time interval that is specified in the question. |
Destination(s) | The list of destination IP addresses associated with this asset, in context of the question tests. If multiple destination IP addresses are associated with this asset and question, this field indicates Multiple and the number of destination IP addresses. The list of destination IP addresses is obtained by filtering the connections that are associated with this question. The obtained list contains all unique destination IP addresses where the asset is the source of the connection. Click Multiple (N) to view the Connections. This display provides the aggregated connections by destination IP address, which is filtered by the asset IP address based on the time interval that is specified in the question. |
Flow Source Bytes | The total source bytes associated with this asset, in context of the question test. The source bytes are determined by filtering the connections that are associated with this question to obtain the source byte total where asset is the source of the connection. |
Flow Destination Bytes | The total destination bytes associated with this asset, in context of the question test. The destination bytes are determined by filtering the connections that are associated with this question to obtain the destination byte total where asset is the destination of the connection. |