19-4
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Incident Details Page
Time ranges for Incidents
The time column displays both single entries for time (Sep 6, 2003 12:09:54 PM PDT), and time ranges
(Sep 6, 2003 12:06:43 PM PDT - Sep 6, 2003 12:06:47 PM PDT).
A single time tells you that all of the firing events were received in the same second. The duration of the
incident includes only events that have fired that incident.
Incident Details Page
Clicking the Incident ID takes you to its Incident Details page. The Incident Details page is rich in
information and information gathering tools. This page answers questions, such as who did it, what event
types happened, when it happened, and to whom it happened.
Figure 19-3
The Incident Details Page
On the top of this page are the tools that let you search for Incident and Session ID and view the Matched
Rule.
To Search for a Session ID or Incident ID
Step 1
Enter the ID into the appropriate field.
Step 2
Click the
Show
button.
To view a partially hidden rule
Click the Show button next to the Rule Description.