Investigating An Event Or Events - Novell SENTINEL RAPID DEPLOYMENT 6.1 - 12-2009 User Manual

Table of Contents

Advertisement

3.9 Investigating an Event or Events

The right-click option Investigate allows you to:
Perform an event query for the last hour on a single event for:
Other events with the same target IP address
Other events with the same source (initiator) IP address
Other targets with the same event name
NOTE: You cannot perform a query on a null (empty) field.
Graphically display the mappings between any two fields in the selected events. This is
particularly useful to view the relationship between the initiators (IP, port, event, sensor type,
Collector) and the targets (IP, port, event, sensor type, Collector name) of the selected events,
but any fields can be used
Figure 3-5
is an illustration of initiator IP addresses mapped to target IP addresses.
Graph Mapper
Figure 3-5
Section 3.9.1, "Investigate: Event Query," on page 66
Section 3.9.2, "Investigate: Graph Mapper," on page 66
Section 3.9.3, "Historical Event Query," on page 67
Section 3.9.4, "Active Browser," on page 68
Active Views Tab
65

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel rapid deployment 6.1

Table of Contents