STRM Users Guide
Viewing Flows
161
c
If you select
Source IP
,
Destination IP
,
Destination network
,
Source ASN
,
Destination ASN
,
Source TOS
,
Destination TOS
,
Source ifIndex,
Destination ifIndex
,
Source TCP Flags
,
Destination TCP flags
,
Source
Network/ Application
,
Source IP/ Destination Port/ Protocol
,
Source IP/
Application
,
Destination IP/ Application
,
Destination IP/ Protocol
,
Source
IP/ Destination IP/ Destination Port/ Protocol
, or
Destination IP/
Application
:
Note:
The column layout of the data depends on the chosen aggregate option.
Graphs
Displays a bar chart representing the top 10 aggregates,
depending on the chosen aggregate option. Click
Hide Chart
if
you wish to remove the graph from your display.
Legend Reference A colored box in this field associated this flows to the graph.
IP
Specifies the IP address associated with this flow.
Bytes In
Specifies the number of bytes sent to the IP address.
Bytes Out
Specifies the number of bytes sent from the IP address.
Total Bytes
Specifies the total number of bytes associated with this IP
address.
Packets In
Specifies the number of packets sent to the IP address.
Packets Out
Specifies the number of packets sent from the IP address.
Total Packets
Specifies the total number of packets associated with this IP
address.
Host Count
Specifies the number of hosts the IP address has communicated
with.
Count
Specifies the number of flows the IP address has sent or
received.
Table 7-6
Aggregate Parameters
Parameter
Description
Current Filters
The top of the table displays the details of the filter applied to the
search results. To clear these filter values, click
Clear Filter.
Graphs
Displays a bar chart representing the top 10 aggregates,
depending on the chosen aggregate option. Click
Hide Chart
if
you wish to remove the graphs from your display.
Legend Reference A colored box in this field associated this flows to the graph.
Source IP
Specifies the source IP address of the flow.
Source Network
Specifies the source network of the flow. If there are multiple
source networks associated with this event, this field indicates
Multiple and the number.
Destination IP
Specifies the destination IP address of the flow. If there are
destination IP addresses associated with this event, this field
indicates Multiple and the number.
Table 7-5
Source or Destination Parameters (continued)
Parameter
Description
Содержание SECURITY THREAT RESPONSE MANAGER 2008.2 R2 - LOG MANAGEMENT ADMINISTRATION GUIDE REV 1
Страница 13: ...STRM Users Guide Assets 7 Note For more information see Chapter 8 Managing Assets...
Страница 100: ...STRM Users Guide 94 INVESTIGATING OFFENSES...
Страница 138: ......
Страница 226: ......