Adding a Normalization Policy

  1. Go to Settings >> Configuration >> Normalization Policies.

  2. Click Add.

../_images/UEBA_Config_Norm_Policy.png

Adding a Normalization Policy

  1. Enter a Policy Name.

  2. Select the required normalization packages and compiled normalizers only. LogPoint provides the following normalization packages and compiled normalizers to normalize the Active Directory, web proxy, email, VPN, printer, authentication, and resource access logs.

    1. Windows Active Directory

      1. LPA_Windows

    2. Web Proxy

      1. WebsenseWebproxyCompiledNormalizer

      2. LP_BlueCoat ProxySG

      3. LP_Squid

      4. LP_Squid dynamic

      5. LP_Websense Webproxy

    3. Email

      1. CiscoIronPortESGCompiledNormalizer

      2. QmailCompiledNormalizer

      3. SendMailCompiledNormalizer

      4. EximMTACompiledNormalizer

      5. ExchangeMTCompiledNormalizer

      6. ProofPointCompiledNormalizer

      7. MimecastCompiledNormalizer

      8. LP_O365 Exchange MT

    4. VPN

      1. PaloAltoNetworkFirewallCompiledNormalizer

      2. FortiOSCompiledNormalizer

      3. LP_Cisco PIXASA

      4. LP_Juniper PulseSecure

    5. Printer

      1. LPA_Windows

    6. Authentication

      1. Office365CompiledNormalizer

      2. CiscoISEcompiledNormalizer

    7. Resource Access

      1. Office365CompiledNormalizer

      2. EMCIsilonFSCompiledNormalizer

  3. Click Submit.

Note

Go to Adding a Normalization Policy for more details.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support