Event Breakdown of Data
Top N Reports
4-4 Enterasys IPS Analysis and Reporting Guide
Event Breakdown of Data
Double clicking on a data group in the Top N report chart opens a pane on the right side of the
main window and displays a chart illustrating the top 10 event breakdown of the data group, as
shown in
Figure 4-3
on page 4-5. Single clicking on a section in the right hand chart causes those
event details to be displayed in the lower event detail pane.
Attacks by Source Network
Displays the top event counts categorized as ATTACKs by source
network over the time period specified by the
Filter
value. The
value of “N” is 10 by default, but can be changed in the
Top
field.
If high counts are occurring from internal protected networks, this
could indicate a need to investigate and correct the cause.
If the source networks are external, it could indicate that certain IP
addresses or networks should be restricted from access.
Attacks by Destination Network
Displays the top event counts categorized as ATTACKs by
destination network over the time period specified by the
Filter
value. The value of “N” is 10 by default, but can be changed in the
Top
field.
Attacks by Destination Address
Displays the top event counts categorized as ATTACKs by
destination address over the time period specified by the
Filter
value. The value of “N” is 10 by default, but can be changed in the
Top
field.
Compromisers by Destination Network Displays the top event counts categorized as COMPROMISE by
destination network over the time period specified by the
Filter
value. The value of “N” is 10 by default, but can be changed in the
Top
field.
Compromisers by Source Network
Displays the top event counts categorized as COMPROMISE by
source network over the time period specified by the
Filter
value.
The value of “N” is 10 by default, but can be changed in the
Top
field.
Compromisers by Source Address
Displays the top event counts categorized as COMPROMISE by
source address over the time period specified by the
Filter
value.
The value of “N” is 10 by default, but can be changed in the
Top
field.
Virus by Source Address
Displays the top event counts categorized as VIRUS by source
address over the time period specified by the
Filter
value. The
value of “N” is 10 by default, but can be changed in the
Top
field.
Table 4-1 Top N Reports (Continued)
Report
Description
Содержание Intrusion Prevention System
Страница 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Страница 2: ......
Страница 10: ...viii...
Страница 48: ...Platform Specific Dashboard Details System Dashboard 2 22 Enterasys IPS Analysis and Reporting Guide...
Страница 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Страница 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Страница 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...
Страница 120: ...Managing Reports Legacy Reporting 11 32 Enterasys IPS Analysis and Reporting Guide Figure 11 31 Event Ratios by Day...