231
Reporting
About top-level report types
Reports of top events
Symantec Network Security generates the following top-level event reports:
Table 9-1
Types of top-level event reports
Type
Description
Top event types
The Top Event Types report lists the event types, such as
Synflood, Telnet DoS and Portscan, that occurred most frequently
during the specified time period, and the number of times each
event type occurred.
Also specify the maximum number of unique event types to
display. For example, generate a report on the top 10 unique
events or top 100 unique events. To view the number of times any
event type occurred, hover the cursor over the event. Symantec
Network Security generates the Top Event Types report in the
table, pie chart and bar chart formats.
You can generate several drill-down reports for each event type
listed in the Top Event Type report.
Top event
destinations
The Top Event Destinations report lists the most frequently
occurring destination IP addresses of detected events.
However, the top event destinations do not necessarily map to the
top event types. You must specify the report start and end
date/time, and number of unique addresses to display. For
example, you could generate a report on the top 10 addresses or
top 100 addresses. Symantec Network Security generates the Top
Event Type report in the table, pie chart and bar chart formats. To
view the number of times an IP address was an event destination
during the report time period, hover the cursor over the table row,
pie piece, or bar corresponding to the event destination. You can
generate several drill-down reports for each event type listed in
the Top Event Destinations report.
Top event sources
The Top Event Sources report lists the IP addresses that were
most frequently the source addresses of detected events.
You specify the report start and end date/time, and the maximum
number of unique addresses to display. Symantec Network
Security generates this report in the table, pie chart and bar chart
formats. To view the number of times an event source occurred
during the report time period, hover the cursor over the table row,
pie piece or bar corresponding to the event source. You can
generate several drill-down reports for each event type listed in
the Top Event Sources report.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...