327
SQL reference
Using Oracle tables
devid
varchar(33)
Indicates the ID of the device (
deviceID
from
topology table) where the best event was
detected.
Used internally
devName
varchar(33)
Indicates the device name of the best event.
eventNum
integer
Indicates the eventNum of the best event. This is
the event that best represents this incident
(usually the one with the highest severity).
family
varchar(33)
Indicates the family of the best event.
flowcookie
varchar(1025)
Indicates the flowcookie of the best event.
hasNote
integer
Indicates whether there are annotations for this
incident.
0 = no annotations
1 = has annotations
ident
varchar(33)
Indicates the unique identifier for each type of
message.
ifaceid
varchar(33)
Indicates the ID of the interface (
interfaceID
from the topology table) where the best event
was detected.
Used Internally
ifName
varchar(65)
Indicates the actual name of the interface
associated with the best event, corresponding to
ifaceid
.
incidentID
varchar(33)
Indicates the unique string identifying this
incident.
incidRefs
varchar(2049)
Indicates references to other incidents that have
been cross-node correlated using the following
format:
incidentID@nodenum,
incidentID@nodenum, ...
For example:
3d20b47d091e45e8@2,
3d20b45191f6ec72@3
lastEvtTime
integer
Indicates the last time when an event was added
to this incident.
mappedType
varchar(128)
Indicates the mapped type of the event/incident
corresponding to
type
.
module
varchar(33)
Indicates the module name where this incident
was generated.
Used internally
nodeName
varchar(255)
Indicates the hostname of the software or
appliance node, corresponding to
nodeNum
.
Table B-1
Oracle Incident Table
Field Name
Type
Description
Notes
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...