208 Monitoring
Managing incident and event data
Annotating incident data
You can add comments to incidents and events. Each annotation receives a time
stamp and lists the author of the annotation. You can sort multiple annotations
for an event by time stamp in ascending or descending order.
To annotate an incident or event
1
On the
Incidents
tab, double-click an incident or event.
2
Click
Analyst Note
.
3
Enter the information relevant to this incident.
The
Note
field can include guidelines established by the SuperUser, such as
ticket number, owner, and the last action taken in response to the event.
4
Click
Add Note
to preserve your annotation.
5
In
Analyst Note
, click
Close
to save and close.
Note:
All users can annotate incident and event data. See
“User groups
reference”
on page 319 for more about permissions.
Customizing annotation templates
The Network Security console provides an informational template to make
Analyst Notes consistent and pertinent to your enterprise. For example, the
template can prompt for specific information such as identifying numbers or
last actions taken.
Note:
SuperUsers and Administrators can create a template for Analyst Notes.
All users can use the template to annotate incident and event data. See
“User
groups reference”
on page 319 for more about permissions.
To create an annotation template
1
In the Network Security console, click
Configuration
>
Node
>
Analyst Note
Template
.
2
In
Select Node
, select the software or appliance node from the pull-down list
and click
OK
.
3
In the
Analyst Note Template
, edit the file with the boilerplate information
that you want to keep track of, and click
OK
to save and exit.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...