Cisco CS-MARS-20-K9 - Security MARS 20 User Manual page 398

Security mars local controller
Table of Contents

Advertisement

Queries
Event Type Group Ranking
Returns either pre-defined or user defined grouped event types. Ranked by either: number of sessions
containing at least one event type contained in the group or by bytes transmitted in sessions that contain
events that meet the query criteria.
Source IP Address Ranking
Returns source IP addresses. Ranked by number of sessions with that source IP address or by bytes
transmitted in sessions that contain events that meet the query criteria.
Network Ranking
Returns top networks that exists in MARS. Ranked by either: number of sessions that contain events that
meet the query criteria or by bytes transmitted in sessions that contain events that meet the query criteria.
If a network is excluded, it is excluded from all results.
Network Group Ranking
Returns top network groups that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
Source Network Ranking
Returns top source networks that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
Source Network Group Ranking
Returns top source network groups that exists in MARS. Ranked by either: number of sessions that
contain events that meet the query criteria or by bytes transmitted in sessions that contain events that
meet the query criteria. If a network is excluded, it is excluded from all results.
Destination Network Ranking
Returns top destination networks that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
Destination Network Group Ranking
Returns top destination network groups that exists in MARS. Ranked by either: number of sessions that
contain events that meet the query criteria or by bytes transmitted in sessions that contain events that
meet the query criteria. If a network is excluded, it is excluded from all results.
Destination IP Address Ranking
Returns destination IP addresses. Ranked by either: number of sessions with that destination IP address
or by bytes transmitted in sessions that contain events that meet the query criteria.
Source Port Ranking
Returns source ports. Ranked by either: number of sessions with that source port or by bytes transmitted
in sessions that contain events that meet the query criteria.
Destination Port Ranking
Returns destination ports. Ranked by either: number of sessions with that destination port or by bytes
transmitted in sessions that contain events that meet the query criteria.
Protocol Ranking
Returns most used protocols. Ranked by either: number of sessions with that protocol or by bytes
transmitted in sessions that contain events that meet the query criteria.
User Guide for Cisco Security MARS Local Controller
20-6
Chapter 20
Queries and Reports
78-17020-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mars 20Mars 50Mars 100Mars 200

Table of Contents