20-18
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Perform a Long-Duration Query Using a Report
Advantages:
•
The report is compiled relatively quickly.
•
You can compile data gathered over a longer time period
Disadvantage
.
This type of query can only be used without any changes to query criteria other than time range, and can
only be used with the following reports:
•
Activity: All - Top Destination Ports
•
Activity: All - Top Destinations
•
Activity: All - Top Event Types
•
Activity: All - Top Reporting Devices
•
Activity: All - Top Sources
•
Activity: Attacks Seen - Top Reporting Devices
•
Activity: Denies - Top Destination Ports
•
Activity: P2P Filesharing/Chat - Top Event Types
•
Activity: Scans - Top Destination Ports
•
Activity: Scans - Top Destinations
•
Activity: Unknown Events - All Events
•
Activity: Web Usage - Top Destinations by Sessions
•
Activity: Web Usage - Top Sources
•
Attacks: All - Top Rules Fired
•
Attacks: All - Top Sources
2.
Performing a batch query.
Advantages:
•
You can modify any of the query criteria.
•
Best suited for data that spans a short time period.
Disadvantages
•
This type of query can be slow and may take a substantial amount of time to complete.
•
Only Admin users can perform a batch query.
If you want to observe activity on your MARS over a long period, you can change the duration of time
over an existing report that runs on a regular basis, such as hourly or daily, whether they are shipped with
the MARS or created by you.
Note
Trying to run a long-duration query using a report that only runs “on demand” has the same effect as
running a query; it can take just as long because it has to compile data, whereas data from the
regularly-run reports has been precompiled on an ongoing basis.
To query using a report, follow these steps:
Step 1
In the
QUERY / REPORTS
tab, click the
Reports
tab to obtain the Main Report window.