Time Ranges For Incidents; Incident Details Page; To Search For A Session Id Or Incident Id - Cisco CS-MARS-20-K9 - Security MARS 20 User Manual

Security mars local controller
Table of Contents

Advertisement

Incident Details Page

Time ranges for Incidents

The time column displays both single entries for time (Sep 6, 2003 12:09:54 PM PDT), and time ranges
(Sep 6, 2003 12:06:43 PM PDT - Sep 6, 2003 12:06:47 PM PDT).
A single time tells you that all of the firing events were received in the same second. The duration of the
incident includes only events that have fired that incident.
Incident Details Page
Clicking the Incident ID takes you to its Incident Details page. The Incident Details page is rich in
information and information gathering tools. This page answers questions, such as who did it, what event
types happened, when it happened, and to whom it happened.
Figure 19-3
On the top of this page are the tools that let you search for Incident and Session ID and view the Matched
Rule.

To Search for a Session ID or Incident ID

Enter the ID into the appropriate field.
Step 1
Click the Show button.
Step 2
To view a partially hidden rule
Click the Show button next to the Rule Description.
User Guide for Cisco Security MARS Local Controller
19-4
The Incident Details Page
Chapter 19
Incident Investigation and Mitigation
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents