Symantec 10521146 Administration Guide - Page 9

Reporting, Setting Maximum Active Incident Life

Page 9 highlights

Contents 9 Chapter 9 Examining event data 196 Managing incident and event data 201 Selecting columns 202 Selecting view filters 205 Marking and annotating 207 Saving, copying, and printing data 209 Emailing incident or event data 211 Tuning incident parameters 213 Setting Incident Idle Time 213 Setting Maximum Incidents 214 Setting Maximum Active Incident Life 214 Setting Incident Unique IP Limit 215 Setting Event Correlation 'Name' Weight 215 Event Correlation 'Source IP' Weight 216 Event Correlation 'Destination IP' Weight 217 Event Correlation 'Source Port' Weight 217 Event Correlation 'Destination Port' Weight 218 Monitoring flow statistics 219 Enabling flow data collection 219 Configuring FlowChaser 220 Reporting About reports and queries 223 Scheduling reports 224 Adding or editing report schedules 224 Refreshing the list of reports 225 Deleting report schedules 226 Managing scheduled reports 226 Reporting top-level and drill-down 228 About report formats 228 About report types 229 About incident/event reports 229 Printing and saving reports 230 About top-level report types 230 Reports of top events 231 Reports per incident schedule 232 Reports per event schedule 233 Reports by event characteristics 233 Reports per Network Security device 235 Drill-down-only reports 236 Querying flows 237 Viewing current flows 238 Viewing Flow Statistics 239

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

9
Contents
Examining event data
...............................................................................
196
Managing incident and event data
..................................................................
201
Selecting columns
......................................................................................
202
Selecting view filters
.................................................................................
205
Marking and annotating
...........................................................................
207
Saving, copying, and printing data
.........................................................
209
Emailing incident or event data
..............................................................
211
Tuning incident parameters
............................................................................
213
Setting Incident Idle Time
........................................................................
213
Setting Maximum Incidents
.....................................................................
214
Setting Maximum Active Incident Life
..................................................
214
Setting Incident Unique IP Limit
............................................................
215
Setting Event Correlation ±Name° Weight
.............................................
215
Event Correlation ±Source IP° Weight
.....................................................
216
Event Correlation ±Destination IP° Weight
............................................
217
Event Correlation ±Source Port° Weight
.................................................
217
Event Correlation ±Destination Port° Weight
........................................
218
Monitoring flow statistics
................................................................................
219
Enabling flow data collection
...................................................................
219
Configuring FlowChaser
...........................................................................
220
Chapter
9
Reporting
About reports and queries
................................................................................
223
Scheduling reports
............................................................................................
224
Adding or editing report schedules
.........................................................
224
Refreshing the list of reports
...................................................................
225
Deleting report schedules
.........................................................................
226
Managing scheduled reports
....................................................................
226
Reporting top-level and drill-down
.................................................................
228
About report formats
................................................................................
228
About report types
.....................................................................................
229
About incident/event reports
..................................................................
229
Printing and saving reports
.....................................................................
230
About top-level report types
............................................................................
230
Reports of top events
................................................................................
231
Reports per incident schedule
.................................................................
232
Reports per event schedule
......................................................................
233
Reports by event characteristics
.............................................................
233
Reports per Network Security device
.....................................................
235
Drill-down-only reports
............................................................................
236
Querying flows
...................................................................................................
237
Viewing current flows
...............................................................................
238
Viewing Flow Statistics
.............................................................................
239