19-5
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Incident Details Page
Incident Details Table
Each row of the Incident Details table represents either a session or the information common to a group
of sessions. You can see all of the collapsed session information by clicking the plus signs to expand the
group. You can expand or collapse all of the incident’s information by clicking the
Expand All
or
Collapse All
buttons.
Figure 19-4
Expanding a Row in a Table’
This high-density information table lets you drill deep into incidents. Click the Query icon anywhere
on this page to query on a particular criteria. Click the Raw Events
icon for raw events for a particular
session. You can click the
Tune
link to tune incidents for False Positives, see
The False Positive Page,
page 19-8
or click the
Mitigate
link to mitigate an attack.
Figure 19-5
Incident Table
143426
1
Incident ID
2
Severity icon
3
Path and Incident Vector icons. Launch popup
windows to display Path and Incident Vector
diagrams (L2 or L3 attack path information)
4
Offset number
5
Links to Session and Incident Detail pages of
all incidents within the session
6
Links to the Event Type Details pages
143425
1
2
12
7
4
5
6
3
8
9
10
11