* Aaron [TF]

  • Total activity 77
  • Last activity
  • Member since
  • Following 0 users
  • Followed by 0 users
  • Votes 0
  • Subscriptions 39

Articles

Recent activity by * Aaron [TF] Sort by recent activity Recent activity Votes
  • No new events / events are not importing

    This is a tough one, and one of the most common problems we see. Aanval is an event management console, so events being critical and central to the operation of the console, it is a common issue th...

  • How do I do a full reset on Aanval?

    Aanval's command line utility has a reset option that will reset Aanval to a new installation. It will delete all event data, reset the sqlite database, clear cache, delete licenses, etc. It cannot...

  • Can Aanval be configured to use a proxy server?

    Aanval's web-interface as well as background processing units (BPUs) are fully proxy compatible. Visit the Proxy display under the Configuration section of the console, where you can enable, select...

  • Does Aanval support Suricata?

    Yes, Aanval fully supports Suricata for both local and remote sensors, including configuration management, signatures, stopping and starting the processes and more. If you are using Suricata, you w...

  • Signature Management

    In Aanval, Snort and Suricata signatures are managed in a dedicated Signature Management display that is accessed through the Policy display. Select a policy, then select the Signatures button. On...

  • Policies

    Policies within Aanval define the specific parameters for sensors in relation to Aanval. More specifically they manage signatures, and other important details of local and remote Snort and Suricata...

  • How do I delete events?

    To delete events in Aanval, simply perform a search for the events you would like to permanently delete from the system, and select the delete button. You will be redirected to a delete confirmatio...

  • Tags

    Tags are a basic function of most modern systems, and are similar to labels. A tag can be attached to a host or an event, and can be used to perform searches as well as reported on. Tags are differ...

  • Incidents

    Incidents are collections of events and hosts with a start time and end time. Incidents are an administrative function of Aanval that can be used to logically group events, hosts and notes together...

  • What is an incident in Aanval?

    In Aanval, an incident is a collection of events and hosts with a start time and end time. Incidents can be used to logically group items together to form an administrative "Incident" tha...