![Enterasys Intrusion Prevention System Скачать руководство пользователя страница 107](http://html1.mh-extra.com/html/enterasys/intrusion-prevention-system/intrusion-prevention-system_reporting-manual_2414787107.webp)
Legacy Reporting
Using the Forensics Console
Enterasys IPS Analysis and Reporting Guide 11-19
Figure 11-21 Dragon Forensics Console Tool
2.
Click
Tool
in the left navigation area.
The tool pulldown menu appears in the display area.
3.
Select the desired tool from the tool pulldown.
Table 11-2 Forensics Tools
Forensics
Tool
Description
sum_event
Produces a list of each unique event types detected, the number of the events which have
occurred, and a 24-hour time line marking the hours where each event has occurred. Many
sorting options are available such as sorting based on CIDR blocks, event groups and
direction.
In the 2D-bar chart mode, clicking on a group name displays a list of events associated with
the group of events.
In the list or direction output modes, clicking on a unique event name produces a mklog
report.
sum_ip
Produces a list of unique IP addresses or CIDR blocks that have occurred in a 24-hour
period. The tool can filter based on direction, event types, and many other parameters.
sum_db
Reports high level statistics on a dragon.db file such as the number of events, a break-out
of stats for each Dragon Network Sensor or Dragon Host Sensor, and bytes of data stored.
mklog
Produces a hex dump of events.
Clicking on IP addresses produces a new mklog report with the IP address as a filter.
Clicking on an event name produces a new mklog report with the event name as a filter.
Clicking on a source or destination port launches a mksession tool with the intent of
reconstructing the session associated with the event. The maximum amount of events
listed can be selected from a pulldown menu in the output mode filter.
Содержание Intrusion Prevention System
Страница 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Страница 2: ......
Страница 10: ...viii...
Страница 48: ...Platform Specific Dashboard Details System Dashboard 2 22 Enterasys IPS Analysis and Reporting Guide...
Страница 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Страница 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Страница 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...
Страница 120: ...Managing Reports Legacy Reporting 11 32 Enterasys IPS Analysis and Reporting Guide Figure 11 31 Event Ratios by Day...