Symantec 10521146 Administration Guide - Page 206

Selecting event filters, Maximum Incidents Within Incident Hours

Page 206 highlights

206 Monitoring Managing incident and event data ■ Click Hide Marked to show only the incidents that have not been marked in the Network Security console. ■ Click Show Both to include both marked and unmarked incidents. 5 In Analyst Notes, do one of the following: ■ Click Hide Unannotated to show only incidents with annotations and incidents that contain events with annotations. ■ Click Hide Annotated to show only incidents that do not have annotations or that contain events with annotations. ■ Click Show Both to include both annotated and unannotated incidents. 6 In Node List, do one of the following: ■ In Show Incidents from Node #, click 1 from the pull-down list to show only incidents from the selected software or appliance node, or All (except standby) to view incidents from all the software or appliance nodes within the topology excluding standby nodes. ■ Click Include Backup Nodes to preserve incidents during a failover scenario. 7 In Incident Hours, do one of the following: ■ In Maximum Incident Hours to Display, enter a value to limit the total number of hours. ■ In Maximum Incidents Within Incident Hours, enter a value to limit the total number of incidents within the hour limit. 8 Click Apply to save and exit. Note: All users can select incident filtering criteria. See "User groups reference" on page 319 for more about permissions. Selecting event filters You can filter the event data that is displayed by using the Event Filter. To filter the view of events 1 On the Incidents tab, in the Events at Selected Incident pane, click Filters. 2 In Event Class, do one of the following; ■ Click Hide Operational to show only those events classified as sensor events. ■ Click Hide Sensor to show only events associated with notices.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

206
Monitoring
Managing incident and event data
Click
Hide Marked
to show only the incidents that have not been
marked in the Network Security console.
Click
Show Both
to include both marked and unmarked incidents.
5
In
Analyst Notes
, do one of the following:
Click
Hide Unannotated
to show only incidents with annotations and
incidents that contain events with annotations.
Click
Hide Annotated
to show only incidents that do not have
annotations or that contain events with annotations.
Click
Show Both
to include both annotated and unannotated incidents.
6
In
Node List
, do one of the following:
In
Show Incidents from Node #
, click
1
from the pull-down list to show
only incidents from the selected software or appliance node, or
All
(except standby)
to view incidents from all the software or appliance
nodes within the topology excluding standby nodes.
Click
Include Backup Nodes
to preserve incidents during a failover
scenario.
7
In
Incident Hours
, do one of the following:
In
Maximum Incident Hours to Display
, enter a value to limit the total
number of hours.
In
Maximum Incidents Within Incident Hours
, enter a value to limit
the total number of incidents within the hour limit.
8
Click
Apply
to save and exit.
Note:
All users can select incident filtering criteria. See
²User groups reference³
on page 319 for more about permissions.
Selecting event filters
You can filter the event data that is displayed by using the Event Filter.
To filter the view of events
1
On the
Incidents
tab, in the
Events at Selected Incident
pane, click
Filters
.
2
In
Event Class
, do one of the following;
Click
Hide Operational
to show only those events classified as sensor
events.
Click
Hide Sensor
to show only events associated with notices.