Symantec 10268947 User Guide - Page 99

Monitoring events, Viewing event data

Page 99 highlights

Incidents and Events 99 Monitoring events 6 In Node List, do one of the following: ■ In Show Incidents from Node #, click 1 from the pull-down list to show only incidents from the selected software or appliance node, or All (except standby) to view incidents from all the software or appliance nodes within the topology excluding standby nodes. ■ Click Include Backup Nodes to preserve incidents during a failover scenario. 7 In Incident Hours, do one of the following: ■ In Maximum Incident Hours to Display, enter a value to limit the total number of hours. ■ In Maximum Incidents Within Incident Hours, enter a value to limit the total number of incidents within the hour limit. 8 Click Apply to save and exit. See the following for related information: ■ See "Marking incidents as viewed" on page 95. Monitoring events An incident is a possible attack composed of multiple related events. When the sensor detects a suspicious event, it correlates the event to an incident containing related events. Event types are group names for one or more base events. Incidents consist of one or more event types, and event types consist of one or more base events. The Network Security console displays event data in the lower pane below the Incident table. With any account, you can annotate events and mark incidents to improve incident tracking, management, assignment, and response to enterprise threats. Viewing event data The Incidents tab contains an upper and lower pane: Incidents, and Events at Selected Incident. In the upper pane, information about each incident is displayed. View the event data that is specific to a particular incident by clicking the respective incident row. The related event information is then displayed in the lower pane. To view event data 1 In the Incidents tab, click an incident row. 2 Related events are displayed in the lower Events at Selected Incident pane.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

99
Incidents and Events
Monitoring events
6
In
Node List
, do one of the following:
In
Show Incidents from Node #
, click
1
from the pull-down list to show
only incidents from the selected software or appliance node, or
All
(except standby)
to view incidents from all the software or appliance
nodes within the topology excluding standby nodes.
Click
Include Backup Nodes
to preserve incidents during a failover
scenario.
7
In
Incident Hours
, do one of the following:
In
Maximum Incident Hours to Display
, enter a value to limit the total
number of hours.
In
Maximum Incidents Within Incident Hours
, enter a value to limit
the total number of incidents within the hour limit.
8
Click
Apply
to save and exit.
See the following for related information:
See
“Marking incidents as viewed”
on page 95.
Monitoring events
An incident is a possible attack composed of multiple related events. When the
sensor detects a suspicious event, it correlates the event to an incident
containing related events. Event types are group names for one or more base
events. Incidents consist of one or more event types, and event types consist of
one or more base events. The Network Security console displays event data in
the lower pane below the Incident table.
With any account, you can annotate events and mark incidents to improve
incident tracking, management, assignment, and response to enterprise threats.
Viewing event data
The Incidents tab contains an upper and lower pane:
Incidents
, and
Events at
Selected Incident
. In the upper pane, information about each incident is
displayed. View the event data that is specific to a particular incident by clicking
the respective incident row. The related event information is then displayed in
the lower pane.
To view event data
1
In the
Incidents
tab, click an incident row.
2
Related events are displayed in the lower
Events at Selected Incident
pane.