20-15
User Guide for Cisco Security MARS Local Controller
78-17020-01
Chapter 20 Queries and Reports
Viewing Events in Real-time
Only
All Marching Events
, and
All Matching Events Raw Messages
have the
Raw events
option.
All Matching Events
with
Raw events
displays Event ID, Event Type, Source IP/Port,
Destination IP/Port, Protocol Time, and Reporting Device fields.
All Matching Events Raw Messages
with
Raw events
displays Event ID, Event Type, Time,
Reporting Device, and Raw Message fields.
A Result Format with the
Sessionized Events
option
displays Event/Session/Incident ID, Event
Type, Source IP/Port, Destination IP/Port, Protocol, Time, Reporting Device, Path/Mitigation,
and Tune fields.
c.
Click
Apply
.
The Query Event Data screen appears with the
Save as Report
and
Save as Rule
buttons gray and
inactive, as shown in
Figure 20-15
.
Figure 20-15
Real-Time Event Query to Submit
Step 4
Modify the parameters of the Query Event Data filter as you require and click
Submit
.
Note
The Operation, Rule, and Action parameters of the Query Event Data filter do not function for
the real-time event viewer.
Real-time results begin to scroll up from the bottom of the page within 5 seconds, as shown in
Figure 20-16
. Real-time raw events are shown in this example.
Содержание CS-MARS-20-K9 - Security MARS 20
Страница 20: ...Contents xx User Guide for Cisco Security MARS Local Controller 78 17020 01 ...
Страница 356: ...17 16 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 17 Network Summary Summary Page ...
Страница 420: ...20 28 User Guide for Cisco Security MARS Local Controller 78 17020 01 Chapter 20 Queries and Reports Reports ...
Страница 580: ...Glossary GL 4 User Guide for Cisco Security MARS Local Controller 78 17020 01 ...