Symantec 10268947 User Guide - Page 95

Viewing priority color codes, Annotating incidents and events, Marking incidents as viewed, Incidents

Page 95 highlights

Incidents and Events 95 About incidents and events To view incident data ◆ In the Network Security console, click the Incidents tab. All users can modify the view by adjusting font size, selecting and sorting columns, and/or applying filters. Viewing priority color codes All users can sort the incident data by clicking on the column heading. The toggle sorts the column in ascending or descending order. To sort the incidents ◆ Do one of the following: ■ Click the heading of the column you want to sort. ■ Click the column heading again to reverse the order. Annotating incidents and events You can add comments to incidents and events. Each annotation receives a time stamp and lists the author of the annotation. You can sort multiple annotations for an event by time stamp in ascending or descending order. To annotate an incident or event 1 On the Incidents tab, double-click an incident or event. 2 Click Analyst Note. 3 Enter the information relevant to this incident. The Note field can include guidelines established by the SuperUser, such as ticket number, owner, and the last action taken in response to the event. 4 Click Add Note to preserve your annotation. 5 In Analyst Note, click Close to save and close. Marking incidents as viewed All users can mark incidents to distinguish new incidents from reviewed incidents. To mark incidents already viewed 1 On the Incidents tab, right-click an incident. 2 In the pop-up list, click Mark Incident. The Marked column of the incident displays a red hash mark to indicate that it has been viewed.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

95
Incidents and Events
About incidents and events
To view incident data
In the Network Security console, click the
Incidents
tab.
All users can modify the view by adjusting font size, selecting and sorting
columns, and/or applying filters.
Viewing priority color codes
All users can sort the incident data by clicking on the column heading. The
toggle sorts the column in ascending or descending order.
To sort the incidents
Do one of the following:
Click the heading of the column you want to sort.
Click the column heading again to reverse the order.
Annotating incidents and events
You can add comments to incidents and events. Each annotation receives a time
stamp and lists the author of the annotation. You can sort multiple annotations
for an event by time stamp in ascending or descending order.
To annotate an incident or event
1
On the
Incidents
tab, double-click an incident or event.
2
Click
Analyst Note
.
3
Enter the information relevant to this incident.
The
Note
field can include guidelines established by the SuperUser, such as
ticket number, owner, and the last action taken in response to the event.
4
Click
Add Note
to preserve your annotation.
5
In
Analyst Note
, click
Close
to save and close.
Marking incidents as viewed
All users can mark incidents to distinguish new incidents from reviewed
incidents.
To mark incidents already viewed
1
On the
Incidents
tab, right-click an incident.
2
In the pop-up list, click
Mark Incident
.
The Marked column of the incident displays a red hash mark to
indicate that it has been viewed.