Symantec 10268947 User Guide - Page 119

Viewing exported flows, Flows, Match Source and Destination, Source IP, Source or Destination IP

Page 119 highlights

Reports and Queries 119 About querying flows Viewing exported flows Query Exported Flows enables you to search against flow data that has been logged to the disk database. This enables flow data to be saved when a certain condition is triggered. The result is that a new event appears in the Network Security console with a link to the actual flow data. The search dialog allows the user to search across all the flows that have been exported. To query exported flows 1 In the Network Security console, click Flows > View Exported Flows. 2 Choose one of the following tabs: ■ Match Source and Destination: This will make a more focused query on specific source and destination IPs. ■ Match Source or Destination: This will make a broader query on either a source IP or a destination IP. 3 In Match Source and Destination, you can display only flows that pertain to specific source and destination IPs. To make this more focused query, enter data in the following fields: ■ Source IP: Numeric IP address ■ Port: Valid port number 4 In Match Source or Destination, you can display flows that pertain to either a source IP or a destination IP. To make this broader query, enter data in the following fields: ■ Source or Destination IP: Numeric IP address ■ Port: Valid port number Note: The Network Security console displays the flow data in table format, one page at a time. You can sort the table by clicking the heading of any column. This sort, however, applies only to the page currently displayed, which may be only a portion of the entire report. At the top of the display, a prompt indicates how many flows are currently displayed, out of the total report. 5 Do one of the following: ■ Click Start Query to run a flow query based on the parameters that you configured. ■ Click Next Results to view the next page of a query that was too large to display in its entirety. ■ Click Clear to stop the active query and remove the results from display.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

119
Reports and Queries
About querying flows
Viewing exported flows
Query Exported Flows enables you to search against flow data that has been
logged to the disk database.
This enables flow data to be saved when a certain
condition is triggered. The result is that a new event appears in the Network
Security console with a link to the actual flow data. The search dialog allows the
user to search across all the flows that have been exported.
To query exported flows
1
In the Network Security console, click
Flows
>
View Exported Flows
.
2
Choose one of the following tabs:
Match Source and Destination
: This will make a more focused query
on specific source and destination IPs.
Match Source or Destination
: This will make a broader query on either
a source IP or a destination IP.
3
In
Match Source and Destination
, you can display only flows that pertain to
specific source and destination IPs. To make this more focused query, enter
data in the following fields:
Source IP
: Numeric IP address
Port
: Valid port number
4
In
Match Source or Destination
, you can display flows that pertain to either
a source IP or a destination IP. To make this broader query, enter data in the
following fields:
Source or Destination IP
: Numeric IP address
Port
: Valid port number
Note:
The Network Security console displays the flow data in table format,
one page at a time. You can sort the table by clicking the heading of any
column. This sort, however, applies only to the page currently displayed,
which may be only a portion of the entire report. At the top of the display, a
prompt indicates how many flows are currently displayed, out of the total
report.
5
Do one of the following:
Click
Start Query
to run a flow query based on the parameters that you
configured.
Click
Next Results
to view the next page of a query that was too large to
display in its entirety.
Click
Clear
to stop the active query and remove the results from
display.