334 SQL reference
Using MySQL tables
MySQL event table
The following table describes the structure of the table that Symantec Network
Security uses to export event data to a MySQL database:
severity
integer
Indicates the severity of the best event.
Valid values are 1-10
state
integer
Indicates the state of this incident.
1 = active (currently being
monitored by the AF)
0 = closed (archived to the
db)
time
integer
Indicates the time that the incident record was
last updated.
Standard UNIX time format
(seconds since 1970 GMT)
type
varchar(129)
Indicates the type of the best event.
viewed
integer
Indicates the marked status of this incident.
0 = Not yet marked by a
Network Security console
user.
1 = Marked by a Network
Security console user, and
unchanged since.
2 = Marked by a Network
Security console user, but
has changed since.
Table B-3
MySQL Incident Table
Field Name
Type
Description
Notes
Table B-4
MySQL Event Table
Field Name
Type
Description
Notes
atkaction
integer
Indicates the attempted action.
atkproc
text
Indicates the process name of the attacker, or
blank if not applicable.
atkuser
varchar(255)
Indicates the username of the attacker, or blank if
not applicable.
class
varchar(33)
Indicates the event class.
sniffer
- for
security events
generic
- for
operational events,
etc.
Содержание 10521146 - Network Security 7120
Страница 1: ...Symantec Network Security Administration Guide...
Страница 12: ...12 Contents Index...
Страница 14: ...14...
Страница 70: ...70...
Страница 110: ...110 Populating the topology database Adding nodes and objects...
Страница 158: ...158 Responding Managing flow alert rules...
Страница 188: ...188...
Страница 242: ...242 Reporting Playing recorded traffic...
Страница 268: ...268 Managing log files Exporting data...
Страница 316: ...316 Advanced configuration Configuring advanced parameters...
Страница 317: ...Part IV Appendices The following appendices provide additional reference information User groups reference SQL reference...
Страница 318: ...318...
Страница 338: ...338 SQL reference Using MySQL tables...
Страница 366: ...366 Glossary...
Страница 392: ...392 Index...