Symantec 10268947 User Guide - Page 97

The Incidents tab can display the following incident data, See the following related information

Page 97 highlights

Incidents and Events 97 Monitoring incidents The Incidents tab can display the following incident data: ■ Last Mod. Indicates the date and time when Symantec Network Security Time last modified the incident record. ■ Name Indicates the user group of the current user. ■ Severity Indicates the severity level assigned to the incident. An incident's severity is a measure of the potential damage that it can cause. ■ Source Indicates the IP address of the attack source. If the source is made up of multiple addresses, then the Network Security console displays (multiple IPs) and you can view the list of addresses by double-clicking the event to see Event Details. ■ Destination Indicates the IP address of the attack target. If the destination is made up of multiple addresses, then the Network Security console displays (multiple IPs) and you can view the list of addresses by double-clicking the event to see Event Details. ■ Event Count Indicates the total number of events associated with this incident that have been logged to the database. ■ Device Name Indicates the name of the device where the incident was detected. ■ Location Indicates the location of the device where the incident was detected. ■ State Indicates the condition of the incident, either Active or Closed. Incidents to which no new events have been added for a given amount of time are considered idle, and Symantec Network Security closes them. ■ Marked Indicates whether you marked the incident as viewed. ■ Node # Indicates the number of the software or appliance node that detected the incident. ■ Node Name Indicates the name of the software or appliance node that detected the incident. ■ Other Node Indicates the numbers of the software or appliance node that the #'s incident was cross-node correlated to, if any. See the following related information: ■ See "About incidents and events" on page 91. ■ See "Selecting event columns" on page 100.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

97
Incidents and Events
Monitoring incidents
The Incidents tab can display the following incident data
:
See the following related information:
See
“About incidents and events”
on page 91.
See
“Selecting event columns”
on page 100.
Last Mod.
Time
Indicates the date and time when Symantec Network Security
last modified the incident record.
Name
Indicates t
he user group of the current user.
Severity
Indicates t
he severity level assigned to the incident. An
incident’s severity is a measure of the potential damage that it
can cause.
Source
Indicates t
he IP address of the
attack source.
If the source is
made up of multiple addresses, then the Network Security
console displays
(multiple IPs)
and you can view the list of
addresses by double-clicking the event to see Event Details.
Destination
Indicates t
he IP address of the attack target. If the destination is
made up of multiple addresses, then the Network Security
console displays
(multiple IPs)
and you can view the list of
addresses by double-clicking the event to see Event Details.
Event Count
Indicates the total number of events associated with this incident
that have been logged to the database.
Device Name
Indicates the name of the device where the incident was
detected.
Location
Indicates the location of the device where the incident was
detected.
State
Indicates the condition of the incident, either
Active
or
Closed
. Incidents to which no new events have been added for a
given amount of time are considered idle, and Symantec
Network Security closes them.
Marked
Indicates whether you marked the incident as viewed.
Node #
Indicates the number of the software or appliance node that
detected the incident.
Node Name
Indicates the name of the software or appliance node that
detected the incident.
Other Node
#’s
Indicates the numbers of the software or appliance node that the
incident was cross-node correlated to, if any.