STRM Users Guide
Viewing Events
143
To view aggregate normalized events:
Step 1
Click the
Event Viewer
tab.
The Event Viewer window appears.
Step 2
From the Display drop-down list box, select the desired option. For more
information, see
Table 6-7 Aggregate Normalized Events
.
The event information appears.
Note:
The column layout of the data depends on the chosen display option.
The events window results provides the following information:
Src IP / Dst IP/ Low
Level Cat
Displays a summarized list of events grouped by the source
IP address to destination IP addresses and the low-level
category.
For more information on categories, see the
Event Category
Correlation Reference Guide
.
Table 6-7
Aggregate Normalized Events (continued)
Aggregate Option
Description
Table 6-8
Event Name Parameters
Parameter
Description
Current Filters
The top of the table displays the details of the filter applied to the
search results. To clear these filter values, click
Clear Filter
.
Graphs
Displays a bar chart representing the top 10 aggregates,
depending on the chosen aggregate option. Click
Hide Chart
if
you wish to remove the graph from your display.
Legend Reference A colored box in this field associated this event to the graph.
Event Name
Specifies the normalized name of the event.
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......