19-3
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
The Incidents Page
Figure 19-2
Incidents Navigation
I
The Incident page’s table:
•
Incident ID
An incident’s unique ID.
•
Severity
Low (green), medium (yellow), and high (red) icons.
•
Event Type
The normalized signature sent from the reporting devices.
•
Matched Rule
The rule whose criteria were met.
•
Action
The description of the notification taken when this rule fires (epage, email, etc.)
•
Time
A single time or a time range (see
Time ranges for Incidents, page 19-4
for more information)
•
Incident Path
The icon that takes you to the incident’s path diagram.
•
Incident Vector
The icon that takes you to the source, event type, and destination diagram.
1
The Incident ID— Link to the Incident Detail
page.
2
Incident Severity Icon
3
The events that compose the Incident—
Launches the Event Type Details popup
window.
4
Query icon—Link to the Query page and
populates the corresponding query field with
the item.
5
The rule that fired to create the incident. Links
to the rule page to display the details of the
rule.
6
Time range of the incident.
7
Launches the Incident Path and Incident
Vector diagrams Click to query on the
matched rule
8
Link to the View Case page
143428
4
1
2
3
5
6
7
8