Legacy Reporting
Using the Realtime Console
Enterasys IPS Analysis and Reporting Guide 11-11
EventsScoredByIP
This event summary counts up each IP address’ total score, based on each event’s group score. The
IP addresses with the highest scores are ranked at the top and a rough graph to show how the
scores compare is displayed.
Figure 11-11
is an example score analysis of Finger events.
Figure 11-11 Realtime EventsScoredByIP
Tool
SummaryByIP
The SummaryByIP event summary can be used to list active IP addresses and drill-down views of
CIDR blocks. The CIDR field must be set to a high level CIDR number such as 8 or 16 to get good
performance. Leaving values of 24 or 32 will work, but results in many matches, most of which
cannot be displayed. You may start off by selecting a CIDR block of 8 then drilling down until the
list-events tool is called, listing events from that particular IP address. For each query, a bar chart
indicating the total number of events for that CIDR block is displayed, as shown in
Figure 11-12
.
Figure 11-12 Realtime SummaryByIP
EventSummary
The EventSummary event summary is used to list all active events in the order of the most recent
to the least recent. Each event is printed out with its total number, the last time of the most recent
event and a 48-hour activity strip chart. The strip chart shows a plus sign (+) for each hour that the
event has occurred at least once. The strip chart shows a 48-hour time line that is slightly different
than the 24-hour time line used in the Dragon Forensic Console’s sum_event tool.
Figure 11-13
is
an example output.
Содержание Intrusion Prevention System
Страница 1: ...P N 9034069 13 Enterasys Intrusion Prevention System Analysis and Reporting Guide...
Страница 2: ......
Страница 10: ...viii...
Страница 48: ...Platform Specific Dashboard Details System Dashboard 2 22 Enterasys IPS Analysis and Reporting Guide...
Страница 60: ...Selecting a Chart Type Top N Reports 4 6 Enterasys IPS Analysis and Reporting Guide...
Страница 70: ...Event Growth Report Trending Reports 5 10 Enterasys IPS Analysis and Reporting Guide...
Страница 82: ...Viewing a PCAP File for an Event 8 2 Enterasys IPS Analysis and Reporting Guide...
Страница 120: ...Managing Reports Legacy Reporting 11 32 Enterasys IPS Analysis and Reporting Guide Figure 11 31 Event Ratios by Day...