Modifying Event Mapping
This manual action is used to map unknown log source events to known JSA events so that they can be categorized and processed appropriately.
You can manually map a normalized or raw event to a high-level and low-level category (or QID).
For normalization purposes, JSA automatically maps events from log sources to high- and low-level categories.
For more information about event categories, see the Juniper Secure Analytics Administration Guide.
If events are received from log sources that the system is unable to categorize, then the events are categorized as unknown. These events occur for several reasons, including:
User-defined Events— Some log sources, such as Snort, allows you to create user-defined events.
New Events or Older Events— Vendor log sources might update their software with maintenance releases to support new events that JSA might not support.
The Map Event icon is disabled for events when the high-level category is SIM Audit or the log source type is Simple Object Access Protocol (SOAP).