Symantec 10268947 User Guide - Page 100

Selecting event columns, Incidents, Events at Selected Incidents, Columns, Table Column Chooser

Page 100 highlights

100 Incidents and Events Monitoring events Note: Both StandardUsers and RestrictedUsers can modify the view by selecting which columns to display, sorting columns, and applying view filters. Selecting event columns Not all events contain data in every category, so you may want to remove empty or irrelevant columns, or add others to customize the display. All users can modify the display of event information by selecting columns. To select event columns 1 In the Incidents tab, in the lower Events at Selected Incidents pane, click Columns. 2 In Table Column Chooser, do one of the following: ■ Click Select All to select all columns. ■ Click the individual columns you want to view. 3 Click OK to save and close. The Events at Selected Incident can display the following information: ■ Time Indicates the date and time when Symantec Network Security first detected and logged the event. ■ Event Type Indicates the event category of the detected event. ■ Name Indicates the user group of the current user. ■ Source Indicates the IP address of the packet that triggered the event. If the source is made up of multiple addresses, then the Network Security console displays (multiple IPs) and you can view the list of addresses by double-clicking the event to see Event Details. ■ Destination Indicates the IP address of the attack target. If the destination is made up of multiple addresses, then the Network Security console displays (multiple IPs) and you can view the list of addresses by double-clicking the event to see Event Details. ■ Severity Indicates the severity level assigned to the event. An event's severity is a measure of the potential damage that it can cause.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

100
Incidents and Events
Monitoring events
Note:
Both StandardUsers and RestrictedUsers can modify the view by selecting
which columns to display, sorting columns, and applying view filters.
Selecting event columns
Not all events contain data in every category, so you may want to remove empty
or irrelevant columns, or add others to customize the display. All users can
modify the display of event information by selecting columns.
To select event columns
1
In the
Incidents
tab, in the lower
Events at Selected Incidents
pane, click
Columns
.
2
In
Table Column Chooser
, do one of the following:
Click
Select All
to select all columns.
Click the individual columns you want to view.
3
Click
OK
to save and close.
The
Events at Selected Incident
can display the following information:
Time
Indicates the date and time when Symantec Network Security first
detected and logged the event.
Event
Type
Indicates the event category of the detected event.
Name
Indicates the user group of the current user.
Source
Indicates the IP address of the packet that triggered the event. If
the source is made up of multiple addresses, then the Network
Security console displays
(multiple IPs)
and you can view the
list of addresses by double-clicking the event to see Event Details.
Destination
Indicates the IP address of the attack target. If the destination is
made up of multiple addresses, then the Network Security console
displays
(multiple IPs)
and you can view the list of addresses
by double-clicking the event to see Event Details.
Severity
Indicates the severity level assigned to the event. An event’s
severity is a measure of the potential damage that it can cause.