Does OSSIM permit manual and automatic treating of the alarms?
Yes, OSSIM allows both manual and automatic response to alarms: Manual management: The information panel permits alarms to be analysed in detail by looking at the events that generated it, the devices involved etc. Then further tracking and processing can be performed using the incident manager. Automatic management: This method allows automatic execution of actions to handle the alarm. The particular action to be taken depends upon the policy in force. Even, network perimeter devices such as firewall and routers can be reconfigured to deny access after an intrusion attempt.