Chapter 18: Enterprise Scanner Logs and Alerts
244
IBM Internet Security Systems
Downloading an Alert Log
Introduction
If necessary, you can save an Alert log to a file to use for forensic purposes. You can do
that in the Proventia Manager for your agent.
Note:
Alerts remain on display on the Alerts log page after you save a log.
Three files per log
The Alert log is saved in three comma-separated values (.csv) files. The three files cross-
reference the data displayed in the Alerts log:
Procedure
To download an Alert log file:
1. On the Alerts page in Proventia Manager, click
Generate new log file from Alerts
.
The Log File Management page appears.
2. Select a file to download, and then click
Download
.
A menu prompts, “Are you sure you want to download the file?”
3. Click
OK
.
4. Select
Save
, and then click
OK
.
5. Navigate to the folder where you want to save the file.
6. Type a file name, and then click
Save
.
Log File Name
Contents
filename_eventdata.csv
•
the distinct records that match the alert record number
•
the event name and the risk level
filename_eventinfo.csv
The data listed in the event-specific information section of the
alert.
filename_eventresp.csv
The data from the responses-executed section of the alert.
Table 93:
Three alert log files
Summary of Contents for Proventia Network Enterprise
Page 1: ...IBM Internet Security Systems IBM Proventia Network Enterprise Scanner User Guide Version 1 3 ...
Page 8: ...8 Contents IBM Internet Security Systems ...
Page 14: ...Preface 14 IBM Internet Security Systems ...
Page 15: ...Part I Getting Started ...
Page 16: ......
Page 69: ...Part II Configuring Enterprise Vulnerability Protection ...
Page 70: ......
Page 80: ...Chapter 5 Introduction to Enterprise Scanner Policies 80 IBM Internet Security Systems ...
Page 120: ...Chapter 8 Defining Agent Policies 120 IBM Internet Security Systems ...
Page 121: ...Part III Scanning ...
Page 122: ......
Page 134: ...Chapter 9 Understanding Scanning Processes in SiteProtector 134 IBM Internet Security Systems ...
Page 150: ...Chapter 10 Monitoring Scans 150 IBM Internet Security Systems ...
Page 164: ...Chapter 11 Managing Scans 164 IBM Internet Security Systems ...
Page 165: ...Part IV Analysis Tracking and Remediation ...
Page 166: ......
Page 190: ...Chapter 13 Tracking and Remediation 190 IBM Internet Security Systems ...
Page 197: ...Part V Maintenance ...
Page 198: ......
Page 212: ...Chapter 16 Updating Enterprise Scanner 212 IBM Internet Security Systems ...
Page 218: ...Chapter 16 Updating Enterprise Scanner 218 IBM Internet Security Systems ...
Page 224: ...Chapter 16 Updating Enterprise Scanner 224 IBM Internet Security Systems ...
Page 252: ...Chapter 18 Enterprise Scanner Logs and Alerts 252 IBM Internet Security Systems ...
Page 258: ...Glossary 258 IBM Internet Security Systems ...
Page 268: ......