Symantec 10268947 User Guide - Page 7

Detection Methods, Incidents and Events, Reports and Queries, About Symantec signatures

Page 7 highlights

About custom response action 81 About TCP reset response action 81 About traffic record response action 81 About console response action 82 About export flow response action 82 About flow alert rules 83 Viewing flow alert rules 83 Playing recorded traffic 83 Replaying recorded traffic flow data 84 Chapter 7 Detection Methods About detection 85 About sensor detection 86 Viewing sensor parameters 87 About port mapping 87 Viewing port mappings 87 About signature detection 87 About Symantec signatures 88 About user-defined signatures 88 Viewing signatures 89 About signature variables 89 About refinement rules 89 Chapter 8 Incidents and Events About incidents and events 91 About the Incidents tab 94 Monitoring incidents 96 Viewing incident data 96 Filtering the view of incidents 98 Monitoring events 99 Viewing event data 99 Filtering the view of events 101 Viewing event notices 102 Managing the incident/event data 103 Loading cross-node correlated events 104 Saving, printing, or emailing incidents 104 Chapter 9 Reports and Queries About reports ...109 Reporting via the Network Security console 109 About report formats 110 About top-level report types 110 Contents 7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

7
Contents
About custom response action
..................................................................
81
About TCP reset response action
..............................................................
81
About traffic record response action
.......................................................
81
About console response action
..................................................................
82
About export flow response action
...........................................................
82
About flow alert rules
.........................................................................................
83
Viewing flow alert rules
.............................................................................
83
Playing recorded traffic
.....................................................................................
83
Replaying recorded traffic flow data
........................................................
84
Chapter
7
Detection Methods
About detection
...................................................................................................
85
About sensor detection
.......................................................................................
86
Viewing sensor parameters
.......................................................................
87
About port mapping
............................................................................................
87
Viewing port mappings
..............................................................................
87
About signature detection
.................................................................................
87
About Symantec signatures
.......................................................................
88
About user-defined signatures
..................................................................
88
Viewing signatures
......................................................................................
89
About signature variables
..........................................................................
89
About refinement rules
......................................................................................
89
Chapter
8
Incidents and Events
About incidents and events
...............................................................................
91
About the Incidents tab
..............................................................................
94
Monitoring incidents
..........................................................................................
96
Viewing incident data
.................................................................................
96
Filtering the view of incidents
...................................................................
98
Monitoring events
...............................................................................................
99
Viewing event data
......................................................................................
99
Filtering the view of events
.....................................................................
101
Viewing event notices
...............................................................................
102
Managing the incident/event data
.................................................................
103
Loading cross-node correlated events
...................................................
104
Saving, printing, or emailing incidents
.................................................
104
Chapter
9
Reports and Queries
About reports
.....................................................................................................
109
Reporting via the Network Security console
................................................
109
About report formats
................................................................................
110
About top-level report types
............................................................................
110