20-6
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Queries
•
Event Type Group Ranking
Returns either pre-defined or user defined grouped event types. Ranked by either: number of sessions
containing at least one event type contained in the group or by bytes transmitted in sessions that contain
events that meet the query criteria.
•
Source IP Address Ranking
Returns source IP addresses. Ranked by number of sessions with that source IP address or by bytes
transmitted in sessions that contain events that meet the query criteria.
•
Network Ranking
Returns top networks that exists in MARS. Ranked by either: number of sessions that contain events that
meet the query criteria or by bytes transmitted in sessions that contain events that meet the query criteria.
If a network is excluded, it is excluded from all results.
•
Network Group Ranking
Returns top network groups that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
•
Source Network Ranking
Returns top source networks that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
•
Source Network Group Ranking
Returns top source network groups that exists in MARS. Ranked by either: number of sessions that
contain events that meet the query criteria or by bytes transmitted in sessions that contain events that
meet the query criteria. If a network is excluded, it is excluded from all results.
•
Destination Network Ranking
Returns top destination networks that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
•
Destination Network Group Ranking
Returns top destination network groups that exists in MARS. Ranked by either: number of sessions that
contain events that meet the query criteria or by bytes transmitted in sessions that contain events that
meet the query criteria. If a network is excluded, it is excluded from all results.
•
Destination IP Address Ranking
Returns destination IP addresses. Ranked by either: number of sessions with that destination IP address
or by bytes transmitted in sessions that contain events that meet the query criteria.
•
Source Port Ranking
Returns source ports. Ranked by either: number of sessions with that source port or by bytes transmitted
in sessions that contain events that meet the query criteria.
•
Destination Port Ranking
Returns destination ports. Ranked by either: number of sessions with that destination port or by bytes
transmitted in sessions that contain events that meet the query criteria.
•
Protocol Ranking
Returns most used protocols. Ranked by either: number of sessions with that protocol or by bytes
transmitted in sessions that contain events that meet the query criteria.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...