194 Monitoring
Examining incident and event data
priority level, then the event most recently correlated to the incident is
displayed.
Note:
SuperUsers and Administrators can drill down to view incident details.
See
“User groups reference”
on page 319 for more about permissions.
To view incident details
1
On the
Incidents
tab, in the upper
Incidents
pane, right-click any incident
row.
2
Click
View Incident Details
from the pop-up list.
Incident Details
displays the following information:
3
Click
OK
to exit Incident Details.
From
Incident Details
, you can also do the following:
■
Event name
Indicates the name of the event.
■
Severity level
Indicates the severity level assigned to the
incident. An incident’s severity is a measure of
the potential damage that an incident can cause.
■
Confidence level
Indicates the confidence level assigned to the
incident. The confidence value indicates the level
of certainty that a particular incident is actually
an attack. If the incident is merely suspicious,
then its assigned confidence level is low. If
Symantec Network Security collects more data
on the incident to substantiate its confidence,
the confidence is adjusted upward.
■
End time
Indicates the time at which Symantec Network
Security stopped monitoring the incident.
See
“Setting Incident Idle Time”
on page 213.
■
Node where incident was
detected
Indicates the name of the software or appliance
node on which the top event for this incident was
detected.
■
Source IP address and port
Indicates the IP address and port of the node on
which the top event for this incident was
detected.
■
Destination IP address and
port
Indicates the IP address and port of the node on
which the top event for this incident was
detected.
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...