20-12
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Queries
The reporting devices present in the system. This restricts the query to a subset of the devices that report
to the MARS.
Severity/Zone
•
ANY
No constraint on the event type severity.
•
Green
Low-severity events
•
Yellow
Medium-severity events
•
Red
High-severity events
•
Zone
Events reported by devices in the indicated zone.
Operation
•
None
Defines a single-line query.
•
AND
Boolean “and” that defines a two or more line query.
•
OR
Boolean “or” that defines a two or more line query.
•
FOLLOWED-BY
Time conditional query (e.g.: Y must happen after X) that defines a two or more line query.
Rule
•
Empty field
–
Rules Chosen field
When this field is empty, it acts like an ANY selection. No constraint is placed on the sub-set of events.
•
Rule
Restricts the query to the sub-set of events that contributed to the incidents of the specified rules firing.
Action
•
Empty field
–
Empty Actions Chosen field
When this field is empty, it acts like an ANY selection. No constraint is placed on the sub-set of events.
•
Actions
Restricts the query to the sub-set of events that contributed to the incidents of rules that have the
specified notifications as part of their actions. (See
Table 21-1Rule Fields and Arguments, page 21-6
for
more information.)
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...