Symantec 10268947 User Guide - Page 104

Loading cross-node correlated events, Saving, printing, or emailing incidents

Page 104 highlights

104 Incidents and Events Managing the incident/event data Loading cross-node correlated events If the selected incident is correlated to an incident from another software or appliance node (as denoted in the Other Node # column), then each tab of Incident details will contain one sub-incident of the cross-node incident, and the tab will carry the name of the node that detected that sub-incident. To load events ◆ Click Load Events to load the events for the currently selected sub-incident. Load Events will be disabled if the currently selected sub-incident's events are already loaded. Saving, printing, or emailing incidents All users can view details, save, print, or email incident data, or send it to the clipboard for pasting, together with its associated events, from the Network Security console. You can display the options by double-clicking an incident row and choosing from the menu items on the Incident Details, or by right-clicking an incident row, and choosing from the menu items displayed. Viewing incident details Symantec Network Security provides a deeper level of information about each incident from the Incidents tab. To view incident details 1 In the Network Security console, click the Incident tab. 2 In Incidents, double-click any incident row. 3 In Incident Details, click Top Event to view the highest priority event correlated to that incident. Incident Details can display the following information: ■ Event Mapped Type The event type to which the base event is mapped. ■ Base Event Type The base event mapped to the incident's highest priority event. ■ Incident ID Unique incident identifier assigned to the incident by Network Security. ■ Network Security The name of the Network Security software node on which software node the incident was detected.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

104
Incidents and Events
Managing the incident/event data
Loading cross-node correlated events
If the selected incident is correlated to an incident from another software or
appliance node (as denoted in the
Other Node #
column), then each tab of
Incident details will contain one sub-incident of the cross-node incident, and the
tab will carry the name of the node that detected that sub-incident.
To load events
Click
Load Events
to load the events for the currently selected sub-incident.
Load Events will be disabled if the currently selected sub-incident's events
are already loaded.
Saving, printing, or emailing incidents
All users can view details, save, print, or email incident data, or send it to the
clipboard for pasting, together with its associated events, from the Network
Security console. You can display the options by double-clicking an incident row
and choosing from the menu items on the Incident Details, or by right-clicking
an incident row, and choosing from the menu items displayed.
Viewing incident details
Symantec Network Security provides a deeper level of information about each
incident from the Incidents tab.
To view incident details
1
In the Network Security console, click the
Incident
tab.
2
In
Incidents
, double-click any incident row.
3
In
Incident Details
, click
Top Event
to view the highest priority event
correlated to that incident.
Incident Details can display the following information:
Event Mapped
Type
The event type to which the base event is mapped.
Base Event Type
The base event mapped to the incident’s highest priority
event.
Incident ID
Unique incident identifier assigned to the incident by
Network Security.
Network Security
software node
The name of the Network Security software node on which
the incident was detected.