19-23
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Layer 2 Path and Mitigation Configuration Example
Figure 19-18
Incident Details screen
Step 2
In the
Incident Details screen
, in the same row as the Event Type you want to examine (in this example
we use Windows RPC DCOM Overflow), click the graph icon under the Graph column to view the
topology paths.
•
To view sessions by performing a Query:
Step 1
Click
QUERY / REPORTS
and submit a query using the appropriate query criteria. Note that in our
example, we limit the scope of the query so it runs faster. In the following
Query Event Data screen
we
use the result format
All Matching Sessions
and query events from
Source IP 10.1.252.250
and
Destination IP 65.54.153.118
over the last
10
minutes.