9
Contents
Examining event data ...............................................................................196
Managing incident and event data ..................................................................201
Selecting columns ......................................................................................202
Selecting view filters .................................................................................205
Marking and annotating ...........................................................................207
Saving, copying, and printing data .........................................................209
Emailing incident or event data ..............................................................211
Tuning incident parameters ............................................................................213
Setting Incident Idle Time ........................................................................213
Setting Maximum Incidents .....................................................................214
Setting Maximum Active Incident Life ..................................................214
Setting Incident Unique IP Limit ............................................................215
Setting Event Correlation ‘Name’ Weight .............................................215
Event Correlation ‘Source IP’ Weight .....................................................216
Event Correlation ‘Destination IP’ Weight ............................................217
Event Correlation ‘Source Port’ Weight .................................................217
Event Correlation ‘Destination Port’ Weight ........................................218
Monitoring flow statistics ................................................................................219
Enabling flow data collection ...................................................................219
Configuring FlowChaser ...........................................................................220
Chapter 9
Reporting
About reports and queries ................................................................................223
Scheduling reports ............................................................................................224
Adding or editing report schedules .........................................................224
Refreshing the list of reports ...................................................................225
Deleting report schedules .........................................................................226
Managing scheduled reports ....................................................................226
Reporting top-level and drill-down .................................................................228
About report formats ................................................................................228
About report types .....................................................................................229
About incident/event reports ..................................................................229
Printing and saving reports .....................................................................230
About top-level report types ............................................................................230
Reports of top events ................................................................................231
Reports per incident schedule .................................................................232
Reports per event schedule ......................................................................233
Reports by event characteristics .............................................................233
Reports per Network Security device .....................................................235
Drill-down-only reports ............................................................................236
Querying flows ...................................................................................................237
Viewing current flows ...............................................................................238
Viewing Flow Statistics .............................................................................239
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...