208 Monitoring
Managing incident and event data
Annotating incident data
You can add comments to incidents and events. Each annotation receives a time
stamp and lists the author of the annotation. You can sort multiple annotations
for an event by time stamp in ascending or descending order.
To annotate an incident or event
1
On the
Incidents
tab, double-click an incident or event.
2
Click
Analyst Note
.
3
Enter the information relevant to this incident.
The
Note
field can include guidelines established by the SuperUser, such as
ticket number, owner, and the last action taken in response to the event.
4
Click
Add Note
to preserve your annotation.
5
In
Analyst Note
, click
Close
to save and close.
Note:
All users can annotate incident and event data. See
“User groups
reference”
on page 319 for more about permissions.
Customizing annotation templates
The Network Security console provides an informational template to make
Analyst Notes consistent and pertinent to your enterprise. For example, the
template can prompt for specific information such as identifying numbers or
last actions taken.
Note:
SuperUsers and Administrators can create a template for Analyst Notes.
All users can use the template to annotate incident and event data. See
“User
groups reference”
on page 319 for more about permissions.
To create an annotation template
1
In the Network Security console, click
Configuration
>
Node
>
Analyst Note
Template
.
2
In
Select Node
, select the software or appliance node from the pull-down list
and click
OK
.
3
In the
Analyst Note Template
, edit the file with the boilerplate information
that you want to keep track of, and click
OK
to save and exit.
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...