{tbl.open,width:100%,align:center,heading:System Options}
Event Import Options 
Event Run Limit
Defines the total number of events to import into the console for each run of the background processors.

Lowering this value may decrease cpu utilization, but may cause delays in event importing if new events per 5 seconds is greater than this value.

Increasing this value may increase cpu utilization, but will import events quicker.

 
Data Storage Path (optional)
Default (blank) uses the consoles dataStore/xxxx/ directory structure to store all events by unique id number.

Use a complete path (must be created manually or previously exist) for the above option to store all events by unique id number.

 
  
Permissions Options 
Permissions Checking & Repair
Enables or disables automatic file permissions checking and attempted repairing of incorrect file or directory permissions.  
  
Email Options 
Email Flood Protection
This option protects email recipients from accidental email floods originated by the console.  
Email Flood Threshold
Defines the maximum number of emails to be transmitted by the console for each run of the background processors.  
  
Host Options 
Hostname Lookups
This option enables / disables console address to hostname lookups.  
Hostname Lookup Run Limit
Defines the maximum number of host lookups performed at each run of the processing unit.  
  
Pre Import Configuration 
No Import EditorEdit Filter
This option allows the editing of the "No Import" filter.

This filter is used to block specific types of events from being imported and processed by the console.

 
  
Signature to Risk EditorEdit Filter
This option allows the editing of the "Sig Risk" filter.

This filter is used to perform dynamic signature to risk level conversions during the consoles import operations.

 
  
Miscellaneous 
System Status
This option enables / disables System Status Processing (load averages).

Disabling this feature may increase performance.

 
  
Processor A Iterations
Processor B Iterations
Processor C Iterations
Processor D Iterations
Defines the number if iterations, each background processor will execute before reloading console settings in memory.

Increasing this amount will increase performance *slightly*, however it may delay settings in the console from reaching the BPU's as each BPU only reads settings into memory on the first iteration.

 
  
Processor A Sleep Setting
Processor B Sleep Setting
Processor C Sleep Setting
Processor D Sleep Setting
Defines the length of time in seconds, each background processor will pause between execution iterations.

Increasing this amount will increase performance *slightly*, however it may slow down processing operations.

 
Indexing Options 
Index > Signature ID
Index > Signature Name
Index > Category ID
Index > Category Name
Index > Source IP
Index > Destination IP
Index > Source Port
Index > Destination Port
Index > Protocol
Index > Sensor
Index > Module
Index > Time
Index > Risk Level
Index > Time x Sensor
Index > Signature x Sensor x Time
Index > Level x Sensor x Time
Index > Source x Sensor x Time
Index > Destination x Sensor x Time
Index > Window Size
Index > Header Length
Index > Sequence Number
Index > Acknowledgement
Index > TTL
Index > Signature Text
Index > Payload Text
Select the event data to be indexed for searching when importing events into the console from snort and syslog.

Indexing creates search lookup tables to allow search functionality within the console.

Indexing directly affects system performance; Selecting fewer index options will increase overall performance.

 
Text Indexing Intensity
This option determines the depth at which the console will identify individual search terms (words) from events containing text. Lower values will increase performance, but will lower the amount of available words that can be used to search events.  
Indexing HoursStart Indexing   End Indexing
Defines the hours in which console indexing will take place.

This option can be used to allow indexing to take place outside times of high utilization or during late night and / or slow times.

Index start and end hours should be defined in 24-hour format (0 = 12:00AM, 23 = 11:00PM)

 
Index Run Limit
Defines the total number of events to index (create search records) for each run of the background processors.

Lowering this value may decrease cpu utilization, but may cause delays in events being searchable after they are imported.

Increasing this value may increase cpu utilization, but will index events (make searchable) quicker.

 
Index Storage Path (optional)
Default (blank) uses the consoles indexStore/xxxx/ directory structure to store all event indexes for the respective dataStore.

Use a complete path (must be created manually or previously exist) for the above option to store all event indexes.

 
Rebuild IndexesRebuild Immediately
This operation forces a complete rebuild of the consoles event indexing (search records) system for the selected Data Store.

Performing this operation is necessary if you believe search results are not accurate or reporting may be out of sync.

* This operation can be processor intensive. Progress is available through on the System Status page.

 

{buttonDisplay1("Save Changes")}
{tbl.close}