Symantec 10268947 User Guide - Page 101

Filtering the view of events, Incidents, Events at Selected Incident, Filters, Event Class

Page 101 highlights

Incidents and Events 101 Monitoring events ■ Confidence Indicates the confidence level assigned to the event. An event's confidence is a measure of the level of certainty that it is actually part of an attack. If the event is merely suspicious, then it is assigned a lower confidence level. If Symantec Network Security collects more data on the event to substantiate its confidence, the confidence is adjusted upward. ■ Event Indicates the order in which the event was added to the incident. Number ■ Device Name Indicates the name of the device where the event was detected. ■ Interface Indicates the name of the interface group where the event was Group detected. ■ Location Indicates the location of the device where the event was detected. ■ VLAN ID Indicates the identification of the VLAN where the event was detected. ■ Blocked Indicates whether the event was blocked or not. You can block events only with a 7100 Series appliance node. Note: Both StandardUsers and RestrictedUsers can modify the display of event information by selecting which columns to display, sorting columns, and applying view filters. Filtering the view of events You can filter the event data that is displayed by using the Event Filter. To filter the view of events 1 On the Incidents tab, in the Events at Selected Incident pane, click Filters. 2 In Event Class, do one of the following; ■ Click Hide Operational to show only those events classified as sensor events. ■ Click Hide Sensor to show only events associated with notices. ■ Click Show Both to show all events relating to the selected incident. 3 In Maximum Events to Display, enter a value. The default is 100 events per incident. 4 Click Apply to save and exit.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

101
Incidents and Events
Monitoring events
Note:
Both StandardUsers and RestrictedUsers can modify the display of event
information by selecting which columns to display, sorting columns, and
applying view filters.
Filtering the view of events
You can filter the event data that is displayed by using the Event Filter.
To filter the view of events
1
On the
Incidents
tab, in the
Events at Selected Incident
pane, click
Filters
.
2
In
Event Class
, do one of the following;
Click
Hide Operational
to show only those events classified as sensor
events.
Click
Hide Sensor
to show only events associated with notices.
Click
Show Both
to show all events relating to the selected incident.
3
In
Maximum Events to Display
, enter a value. The default is 100 events per
incident.
4
Click
Apply
to save and exit.
Confidence
Indicates the confidence level assigned to the event. An event’s
confidence is a measure of the level of certainty that it is actually
part of an attack. If the event is merely suspicious, then it is
assigned a lower confidence level. If Symantec Network Security
collects more data on the event to substantiate its confidence, the
confidence is adjusted upward.
Event
Number
Indicates the order in which the event was added to the incident.
Device
Name
Indicates the name of the device where the event was detected.
Interface
Group
Indicates the name of the interface group where the event was
detected.
Location
Indicates the location of the device where the event was detected.
VLAN ID
Indicates the identification of the VLAN where the event was
detected.
Blocked
Indicates whether the event was blocked or not. You can block
events only with a 7100 Series appliance node.