2.9 Investigating an Event or Events
This Investigate options on the Event Menu allow you to:
Perform a Event Query for the last hour on a single event for:
Other events with the same target IP address
Other events with the same source (initiator) IP address
Other targets with the same event name
NOTE: You cannot perform a query on a null (empty) field.
Graphically display the mappings between any two fields in the selected events. This is
particularly useful to view the relationship between the initiatiors (IP, port, event, sensor type,
Collector) and the targets (IP, port, event, sensor type, Collector name) of the selected events,
but any fields can be used
Below is an illustration of initiator IP addresses mapped to target IP addresses.
Graph Mapper
Figure 2-5
2.9.1 Investigate – Event Query
This function allows you to perform Event Query within the last hour for events similar to the
selected event.
To perform an Event Query using the Investigate function:
1 In a Navigator or Snapshot window, right-click an event>Investigate> <select one of three
options below>
Active Views Tab
47