Using the Realtime Console
Legacy Reporting
11-16 Enterasys IPS Analysis and Reporting Guide
You may click Reset to clear all field entries.
3.
Click
Execute
.
The display area is populated with the results of your query.
Filter Management
You can add, edit, or delete filters. Filters are used to fine-tune event summaries.
Add Filters
To add filters:
1.
Click
Filter Management
in the top left navigation area.
2.
Select
Filter Add
from the pulldown menu.
3.
Select the desired filter from the Filters pulldown menu.
4.
Click
Execute
.
The display area is populated with entry fields for the selected field.
5.
Enter the desired information in the fields.
Time Mode
The Time Mode field interacts with the Time Start/Stop field in the following ways:
• “hours” value selected: The number value placed in the Time Start field indicates
number of hours from the current time counting backwards to retrieve the
events. For example, if the value indicates 36, events in the past 36 hours are
retrieved.
• “start” value selected: only the value from the Time Start field is taken into
consideration. Events starting at that specified time are retrieved.
• “stop” value selected: only the value from the Time Stop field is taken into
consideration. Events up to that specified time are retrieved.
• “span” value selected: both values in the Time Start and Time Stop fields are
taken into consideration. Events that occurred between these times are
retrieved.
• “date” value selected: only the value specified in the Time Start field is taken into
consideration. Events that occurred only during the specified date are retrieved.
• “dates” value selected: both values in the Time Start and Time Stop fields are
taken into consideration. Events that occurred between the specified dates
(inclusive) are retrieved.
All other values ignore Time Start and Stop fields.
Sensor Match, Group
Match
These are text fields specifying sensor and/or group names for the realtime filter.
They may contain one or more names of the sensor/group. If more than one name
is specified, the values must be separated by spaces.
IP Match/Filter
These are text fields specifying IP address/mask for the realtime filter. One or more
values can be specified in theses fields. If more than one value is entered, the
values must be separated by spaces.
Table 11-1 Custom Query Field Usage and Description (Continued)
Field
Description
Note:
The DefaultFilter refreshes the screen every minute.
Refresh mode is indicated by a
red number
in the upper right-hand corner of the screen in
parentheses. For example,
(1)
.
Summary of Contents for Intrusion Prevention System
Page 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Page 2: ......
Page 10: ...viii...
Page 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Page 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Page 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...