20-10
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Queries
5.
Enter search text, and click
Search
to move items that match the search criteria from the
Sources
Available
field to the
Sources Selected
field.
6.
To add a new item to the sources, click the
Add
button. To edit or delete an existing source, click
the
Edit
or
Delete
button. See
IP Management, page 23-3
for more information.
7.
Click an item or items in the Sources Selected field, and use the
Remove
button.
8.
To move IP values up into the Sources Selected field, click the
Equal
(Up) icon, or the
Not
Equal
(Up) icon.
9.
Check the radio button next to
IP
or
Range
, and enter an IP address or a range of IP addresses into
their respective fields.
10.
Select items in the Sources Selected field by clicking them. Enter a group name, and click the
Grouped As
button to group them.
11.
Once you have chosen the query criteria that interests you, click
Apply
to return to the Query page.
Repeat this selection process for other query data.
Step 4
Click the
Submit
button to run the query.
Query Criteria
The following list describes the selections in the Query Event Data table.
Source IP
•
Pre NAT source addresses
Specifies that the constraints entered are the session endpoints.
•
Post NAT source addresses
Specifies that the constraints entered are the source as appearing at the destination.
•
ANY
No constraint is placed on the source IP addresses.
•
Variables
Signify any one IP address, only useful for queries in tandem with the same variable.
•
IP addresses
IP addresses present on devices in the system or user entered dotted quads.
•
IP ranges
The range of addresses between two dotted quads.
•
Networks
Topologically valid networks.
•
Devices
The hosts and reporting devices present in the system.