Investigating An Event Or Events; Investigate - Event Query - Novell SENTINEL 6.1 SP2 - 02-2010 User Manual

Table of Contents

Advertisement

2.9 Investigating an Event or Events

This Investigate options on the Event Menu allow you to:
Perform a Event Query for the last hour on a single event for:
Other events with the same target IP address
Other events with the same source (initiator) IP address
Other targets with the same event name
NOTE: You cannot perform a query on a null (empty) field.
Graphically display the mappings between any two fields in the selected events. This is
particularly useful to view the relationship between the initiatiors (IP, port, event, sensor type,
Collector) and the targets (IP, port, event, sensor type, Collector name) of the selected events,
but any fields can be used
Below is an illustration of initiator IP addresses mapped to target IP addresses.
Graph Mapper
Figure 2-5
2.9.1 Investigate – Event Query
This function allows you to perform Event Query within the last hour for events similar to the
selected event.
To perform an Event Query using the Investigate function:
1 In a Navigator or Snapshot window, right-click an event>Investigate> <select one of three
options below>
Active Views Tab
47

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sentinel 6.1 sp2

Table of Contents