198 Monitoring
Examining incident and event data
Note:
SuperUsers can view advanced event details and packet contents;
Administrators, StandardUsers, and RestrictedUsers cannot. See
“User groups
reference”
on page 319 for more about permissions.
To view event details
1
In the Network Security console, click the
Incidents
tab, and select an
Incident
.
2
In
Events at Selected Incident
, right-click an event row.
3
Click
View Event Details
from the pop-up list.
Event Details
can display any or all of the following information:
4
Click
Close
to close Event Details.
■
Event name
Indicates the name of the event type.
■
Severity level
Indicates the severity level assigned to the incident. An
incident’s severity is a measure of the potential damage
that an incident can cause.
■
Confidence level
Indicates the confidence level assigned to the incident.
The confidence value indicates the level of certainty that a
particular incident is actually an attack. If the incident is
merely suspicious, then its assigned confidence level is
low. If Symantec Network Security collects more data on
the incident to substantiate its confidence, the confidence
is adjusted upward.
■
Start time
Indicates the time at which Symantec Network Security
started monitoring the event.
■
Detected At
Indicates summary information about the event such as
the name of the software or appliance node on which the
event was detected, interface, current policy, and MAC
addresses.
■
Attack Details
Provides detailed information about the event.
■
Event Message
Indicates a summary information about the event.
■
Sources and
Destinations
Indicates source and destination IP addresses and ports of
the packet that triggered the event.
■
Event Note
Displays the optional note entered when the current
policy was created, if any.
See
“Annotating an event type in a policy”
on page 127.
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...