Using the Trending Console
Legacy Reporting
11-22 Enterasys IPS Analysis and Reporting Guide
2.
Click
Add Entry
.
The notes entry area is displayed.
3.
Enter your notes.
4.
Click
Submit
.
Your note is added and displayed on screen.
Using the Trending Console
The Dragon Trending Console is used to answer questions about long-term trends and activity.
The tool uses a program to read events from an Event Flow Processor and send them to an SQL
database (MySQL). This tool utilizes SQL queries to build web displays of IP addresses, events, or
search for unique event entries. For each query, the occurrence of the top seven matches over the
selected time range is displayed. The Trending Console is especially useful when you can only
store a week or less worth of events in the Dragon Realtime Console.
To access the Trending Console Main Window and tools:
1.
Click
Trending
in the top right navigation area.
The Trending Console main window appears as shown in
Figure 11-24
. The display area is
populated with data accessed using the Event Summary option of the top left navigation area.
Figure 11-24 Dragon Trending Console Main Window
Event Summaries
You can manipulate data to show a variety of information that summarizes events.
To manipulate event summary data:
1.
Click
Event Summary
in the top left navigation area.
This is the default selection when entering the Trending Console. The display area is
populated with Event Summary information.
Summary of Contents for Intrusion Prevention System
Page 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Page 2: ......
Page 10: ...viii...
Page 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Page 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Page 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...