Using the Trending Console
Legacy Reporting
11-26 Enterasys IPS Analysis and Reporting Guide
3.
Click
Apply
.
The display area is populated with the selected criteria.
The Reset button clears any selected data.
4.
If desired, sort the data by clicking on a column header or the item name.
Creating Additional Reports
The Additional Reports window allows you to enter specific criteria that is used generate
customized information.
To create additional reports:
1.
Click
Additional Reports
in the top left navigation area.
2.
Enter the desired criteria in the entry fields provided.
Only those fields that pertain to your search need be completed. There are no required fields.
Date
Queries can be bound by start and stop times, specified by individual days and,
optionally, times within days. All queries outside of the range are ignored.
Hosts
A list of IP addresses or CIDR blocks can be specified here. The resulting list can be
applied to all the events as one of any type: source address, destination address, or
both. For example, if a single CIDR block is specified and a query only looking for
internal attacks is desired, a setting of both is chosen for the IP Filter menu. Multiple IP
addresses or CIDR blocks can be specified by using the character, &.
For example, data can be entered as
10.100.100.125 & 10.10.10.0/24 & 10.10.20.0/24
Events
Any set of events can be filtered positively or negatively. Short event names, such as
TCP, can be used to search for other events such as TCP-SWEEP and TCP-FRAG.
Clicking on the blue circle question mark also lists all of the current event types in the
database. Multiple events can be specified by using the character, &. For example,
data can be specified as WEB & TCP & DNS.
Table 11-8 Event Detail Options
Column or Item
Description
Date/time
Sort by date and time.
Dir
Directory in which the event occurred.
Source IP
The Source IP address.
Destination IP
The Destination IP address.
Event name
The Name of the Event. You can click the name for a complete description of the
event.
Alarm Data
Alarm data associated with the event.
Table 11-7 Event Detail Buttons (Continued)
Button
Description
Содержание Intrusion Prevention System
Страница 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Страница 2: ......
Страница 10: ...viii...
Страница 48: ...Platform Specific Dashboard Details System Dashboard 2 22 Enterasys IPS Analysis and Reporting Guide...
Страница 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Страница 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Страница 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...
Страница 120: ...Managing Reports Legacy Reporting 11 32 Enterasys IPS Analysis and Reporting Guide Figure 11 31 Event Ratios by Day...