Event Table Pane
Customizing the Event Table Display
Enterasys IPS Analysis and Reporting Guide 6-3
Table 6-2
describes the options in the right-click Action menu.
Customizing the Event Table Display
The following sections describe customizations you can perform on the Event Table pane.
Setting Display Preferences
The
Event Table
pane allows you to set the display preferences by editing the fields in the
preferences bar at the bottom of the pane.
You can set the number of rows to display per page in the
Show per Page
field, and you can move
forward and back through the pages by clicking on the direction arrows next to the
Page
field, as
shown in
Figure 6-3
. You can interactively refresh the display by clicking the circular arrow icon
next to the
Page
field.
Direction
The direction of the event (for example, Internal or External).
Protocol
The protocol used in the event.
Sensor Name
Name of the Dragon sensor that generated the event. In the case of Network
Sensors, this is the Virtual Sensor name.
Details
Any additional details about the event.
Table 6-2 Right-Click Action Menu Options
Option
Description
Event Details
Displays a pop-up window containing details of the event. See
Chapter 7, Event Details
for more information.
Source Address Lookup
Displays a new browser window that attempts to resolve the IP
address using a DNS lookup. Additional publicly-available web
sites that perform address resolution are provided as links on the
browser page.
Destination Address Lookup
Displays a new browser window that attempts to resolve the IP
address using a DNS lookup. Additional publicly-available web
sites that perform address resolution are provided as links on the
browser page.
Session Rebuild
Displays a page with the session information for the selected
event. Applicable to TCP events.
Download PCAP
Provides a download of a PCAP capture file. This file contains the
traffic between the source and destination IP addresses of the
event for the day the event was generated. Applicable to any TCP
event that supports the Dragon mktcpdump CLI tool.
Refer to
Chapter 8, Viewing a PCAP File for an Event
for more
information.
Mail Event
Opens your mail application with the URL for the event in the
content field of the message.
Table 6-1 Event Table Report Columns
Event Detail Column
Description
Содержание Intrusion Prevention System
Страница 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Страница 2: ......
Страница 10: ...viii...
Страница 48: ...Platform Specific Dashboard Details System Dashboard 2 22 Enterasys IPS Analysis and Reporting Guide...
Страница 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Страница 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Страница 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...
Страница 120: ...Managing Reports Legacy Reporting 11 32 Enterasys IPS Analysis and Reporting Guide Figure 11 31 Event Ratios by Day...