18-2
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 18 Case Management
Case Management Overview
•
Audits (for example, regulatory compliance audits)
•
Justifications for modifying ACLs or policy changes
•
Notes for MARS false positive tuning
•
Examples of allowed and prohibited behavior.
The case preserves and displays the selected data as it appeared when the data was added to the case,
regardless of subsequent changes to the MARS state. For example, MARS data can be purged, topology
can change from automatic discoveries or vulnerability scanning, and overall configuration can change
when you edit rules or reports, but the data reported in the case remains the same as the time it was
captured.
Note
As of MARS software version 4.1.1 the Case Management feature replaces the incident escalation
feature.
The Case Management homepage is the Cases subtab of the Incidents tab as shown in
Figure 18-1
.
Figure 18-1
Case Management Tab—Local Controller
All new, assigned, resolved and closed cases can be accessed from the Cases subtab.
To view the contents of a case, click the Case ID number of a case. The View Case page appears, as
shown in
Figure 18-2
.
To generate an HTML document of the
View Case
page content that can be emailed, click
View Case Document
at the bottom of the
View Case
page. Graphs and charts plotted from reports are
also captured in the Case Document.
1
Case Bar
2
Dropdown Display Filters
3
Individual Cases
143455
1
2
3
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...