Symantec 10268947 User Guide - Page 94

About the Incidents tab, Incidents tab, Devices tab, Incidents, Events at, Selected Incident

Page 94 highlights

94 Incidents and Events About incidents and events About the Incidents tab The Network Security console displays incident and event data in the following: ■ Incidents tab: Displays both active and idle incidents. When you select an incident, Events At Selected Incident in the lower pane displays information about the related events. ■ Devices tab: Displays the topology tree. When you select an object in the topology tree, the Network Security console displays related information in the right pane, including a link to security incidents that are currently active on that object. The Incidents tab provides a multi-level view of both incidents and events. Incidents are groups of multiple related base events. Base events are the representation of individual occurrences, either suspicious or operational. The sensors notify the software or appliance node of any suspicious actions or occurrences that might warrant a response, such as a probe. Symantec Network Security also monitors operational occurrences that the user should be aware of, such as a Symantec Network Security license approaching the expiration date. The Incidents tab contains an upper and lower pane: Incidents, and Events at Selected Incident. The upper pane displays information about each incident, taken from the highest-priority event within that incident. The values may change if an event of higher priority is added to the same incident.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

94
Incidents and Events
About incidents and events
About the Incidents tab
The Network Security console displays incident and event data in the following:
Incidents tab
: Displays both active and idle incidents. When you select an
incident, Events At Selected Incident in the lower pane displays information
about the related events.
Devices tab
: Displays the topology tree. When you select an object in the
topology tree, the Network Security console displays related information in
the right pane, including a link to security incidents that are currently
active on that object.
The Incidents tab provides a multi-level view of both incidents and events.
Incidents are groups of multiple related base events. Base events are the
representation of individual occurrences, either suspicious or operational. The
sensors notify the software or appliance node of any suspicious actions or
occurrences that might warrant a response, such as a probe. Symantec Network
Security also monitors operational occurrences that the user should be aware of,
such as a Symantec Network Security license approaching the expiration date.
The Incidents tab contains an upper and lower pane:
Incidents
, and
Events at
Selected Incident
. The upper pane displays information about each incident,
taken from the highest-priority event within that incident. The values may
change if an event of higher priority is added to the same incident.