19-23
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 19 Incident Investigation and Mitigation
Layer 2 Path and Mitigation Configuration Example
Figure 19-18
Incident Details screen
Step 2
In the
Incident Details screen
, in the same row as the Event Type you want to examine (in this example
we use Windows RPC DCOM Overflow), click the graph icon under the Graph column to view the
topology paths.
•
To view sessions by performing a Query:
Step 1
Click
QUERY / REPORTS
and submit a query using the appropriate query criteria. Note that in our
example, we limit the scope of the query so it runs faster. In the following
Query Event Data screen
we
use the result format
All Matching Sessions
and query events from
Source IP 10.1.252.250
and
Destination IP 65.54.153.118
over the last
10
minutes.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...