Symantec 10268947 User Guide - Page 116

Drill-down-only reports

Page 116 highlights

116 Reports and Queries About top-level report types Drill-down-only reports Most top-level report types are also available as drill-down reports within other top-level reports. However, some Network Security console reports are accessible only as drill-down reports from within top-level reports or other drill-down reports. This section describes the following drill-down-only reports. For the incident you select, data is displayed within the Incident List report. Table 9-6 Drill-down-only reports Report Description Incident details This report lists all the events contained in the selected incident or time period, as well as the event end time, the event source and destination IP addresses, and the name of the device where the event was detected. Symantec Network Security generates the Event List report in table format only. You can access this report from within any Incidents or Events report, as well as from within the Top Event Destination and Top Event Source reports. Event list For the incident you select, data is displayed within the Incident List report. Events details The Event Details report displays the data within any Event List report. Sources of event The Sources of Event report lists all of the source IP addresses for the event you select. Symantec Network Security generates this report in table, pie chart and bar chart formats. You can generate this report from within the Top Event Types report. Destinations of event The Destinations of Event report lists all of the destination IP addresses for the event you select. Symantec Network Security generates this report in table, pie chart and bar chart formats. You can generate this report from within the Top Event Types report. Flows by source address This report lists the source IP addresses of flows found on devices with the Flow Status Collection sensor mode enabled. You can generate this report from within the Devices with Flow Statistics report. Flows by destination address This report lists the destination IP addresses of flows found on devices with Flow Status Collection sensor mode enabled. You can generate this report from within the Devices with Flow Statistics report.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

116
Reports and Queries
About top-level report types
Drill-down-only reports
Most top-level report types are also available as drill-down reports within other
top-level reports. However, some Network Security console reports are
accessible only as drill-down reports from within top-level reports or other
drill-down reports. This section describes the following drill-down-only reports.
For the incident you select, data is displayed within the Incident List report.
Table 9-6
Drill-down-only reports
Report
Description
Incident details
This report lists all the events contained in the selected
incident or time period, as well as the event end time, the
event source and destination IP addresses, and the name
of the device where the event was detected. Symantec
Network Security generates the Event List report in table
format only. You can access this report from within any
Incidents or Events report, as well as from within the Top
Event Destination and Top Event Source reports.
Event list
For the incident you select, data is displayed within the
Incident List report.
Events details
The Event Details report displays the data within any
Event List report.
Sources of event
The Sources of Event report lists all of the source IP
addresses for the event you select. Symantec Network
Security generates this report in table, pie chart and bar
chart formats. You can generate this report from within
the Top Event Types report.
Destinations of event
The Destinations of Event report lists all of the
destination IP addresses for the event you select.
Symantec Network Security generates this report in
table, pie chart and bar chart formats. You can generate
this report from within the Top Event Types report.
Flows by source address
This report lists the source IP addresses of flows found
on devices with the Flow Status Collection sensor mode
enabled. You can generate this report from within the
Devices with Flow Statistics report.
Flows by destination address
This report lists the destination IP addresses of flows
found on devices with Flow Status Collection sensor
mode enabled. You can generate this report from within
the Devices with Flow Statistics report.