![Enterasys Intrusion Prevention System Reporting Manual Download Page 58](http://html1.mh-extra.com/html/enterasys/intrusion-prevention-system/intrusion-prevention-system_reporting-manual_2414787058.webp)
Event Breakdown of Data
Top N Reports
4-4 Enterasys IPS Analysis and Reporting Guide
Event Breakdown of Data
Double clicking on a data group in the Top N report chart opens a pane on the right side of the
main window and displays a chart illustrating the top 10 event breakdown of the data group, as
shown in
Figure 4-3
on page 4-5. Single clicking on a section in the right hand chart causes those
event details to be displayed in the lower event detail pane.
Attacks by Source Network
Displays the top event counts categorized as ATTACKs by source
network over the time period specified by the
Filter
value. The
value of “N” is 10 by default, but can be changed in the
Top
field.
If high counts are occurring from internal protected networks, this
could indicate a need to investigate and correct the cause.
If the source networks are external, it could indicate that certain IP
addresses or networks should be restricted from access.
Attacks by Destination Network
Displays the top event counts categorized as ATTACKs by
destination network over the time period specified by the
Filter
value. The value of “N” is 10 by default, but can be changed in the
Top
field.
Attacks by Destination Address
Displays the top event counts categorized as ATTACKs by
destination address over the time period specified by the
Filter
value. The value of “N” is 10 by default, but can be changed in the
Top
field.
Compromisers by Destination Network Displays the top event counts categorized as COMPROMISE by
destination network over the time period specified by the
Filter
value. The value of “N” is 10 by default, but can be changed in the
Top
field.
Compromisers by Source Network
Displays the top event counts categorized as COMPROMISE by
source network over the time period specified by the
Filter
value.
The value of “N” is 10 by default, but can be changed in the
Top
field.
Compromisers by Source Address
Displays the top event counts categorized as COMPROMISE by
source address over the time period specified by the
Filter
value.
The value of “N” is 10 by default, but can be changed in the
Top
field.
Virus by Source Address
Displays the top event counts categorized as VIRUS by source
address over the time period specified by the
Filter
value. The
value of “N” is 10 by default, but can be changed in the
Top
field.
Table 4-1 Top N Reports (Continued)
Report
Description
Summary of Contents for Intrusion Prevention System
Page 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Page 2: ......
Page 10: ...viii...
Page 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Page 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Page 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...