Using the Realtime Console
Legacy Reporting
11-12 Enterasys IPS Analysis and Reporting Guide
Figure 11-13 Realtime EventSummary (48-Hour Time line)
In this example, many events are observed to be active almost all of the time. This usually
indicates a high rate of false positives.
Figure 11-14
shows a more common output on a well-tuned Dragon Network Sensor. Notice the
trailing events and also a much less dense occurrence of any one event.
Figure 11-14 Realtime EventSummary (Well-Tuned)
Figure 11-15 Realtime EventSummary (IPS Events)
Содержание Intrusion Prevention System
Страница 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Страница 2: ......
Страница 10: ...viii...
Страница 48: ...Platform Specific Dashboard Details System Dashboard 2 22 Enterasys IPS Analysis and Reporting Guide...
Страница 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Страница 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Страница 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...
Страница 120: ...Managing Reports Legacy Reporting 11 32 Enterasys IPS Analysis and Reporting Guide Figure 11 31 Event Ratios by Day...