Legacy Reporting
Using the Trending Console
Enterasys IPS Analysis and Reporting Guide 11-23
Figure 11-25 Dragon Trending Console Event Summaries
The activity summary graph is at the top of the display area. For any query, the top seven
events are graphed over the specified query time period. Floating the mouse over the bar
graph reveals the actual number of events for the given event type. The graph can be shifted to
the left or right to expose hidden dates by clicking in the graph region and dragging the graph
left or right. To zoom in on a region of the graph, click on the graph while pressing the Ctrl
key and drag the mouse to select a region.
The top seven events are indexed in a legend to the left of the graph. Filtering certain events
can cause this graph and table to regenerate.
2.
Select the desired information to view by clicking the navigation buttons and selecting the
desired item in the pulldown menu.
Table 11-3 Event Summary Buttons
Button
Description
sensors
A list of available sensors.
date
Queries can be bound by start and stop times, specified by individual days and,
optionally, times within days. All queries outside of the range are ignored.
hosts
A list of IP addresses or CIDR blocks can be specified here. The resulting list can be
applied to all the events as one of any type: source address, destination address, or
both. For example, if a single CIDR block is specified and a query only looking for
internal attacks is desired, a setting of both is chosen for the IP Filter menu. Multiple
IP addresses or CIDR blocks can be specified by using the character, &.
For example, data can be entered as
10.100.100.125 & 10.10.10.0/24 & 10.10.20.0/24
Summary of Contents for Intrusion Prevention System
Page 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Page 2: ......
Page 10: ...viii...
Page 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Page 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Page 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...