Queries
Event Type Group Ranking
•
Returns either pre-defined or user defined grouped event types. Ranked by either: number of sessions
containing at least one event type contained in the group or by bytes transmitted in sessions that contain
events that meet the query criteria.
Source IP Address Ranking
•
Returns source IP addresses. Ranked by number of sessions with that source IP address or by bytes
transmitted in sessions that contain events that meet the query criteria.
Network Ranking
•
Returns top networks that exists in MARS. Ranked by either: number of sessions that contain events that
meet the query criteria or by bytes transmitted in sessions that contain events that meet the query criteria.
If a network is excluded, it is excluded from all results.
Network Group Ranking
•
Returns top network groups that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
Source Network Ranking
•
Returns top source networks that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
Source Network Group Ranking
•
Returns top source network groups that exists in MARS. Ranked by either: number of sessions that
contain events that meet the query criteria or by bytes transmitted in sessions that contain events that
meet the query criteria. If a network is excluded, it is excluded from all results.
Destination Network Ranking
•
Returns top destination networks that exists in MARS. Ranked by either: number of sessions that contain
events that meet the query criteria or by bytes transmitted in sessions that contain events that meet the
query criteria. If a network is excluded, it is excluded from all results.
•
Destination Network Group Ranking
Returns top destination network groups that exists in MARS. Ranked by either: number of sessions that
contain events that meet the query criteria or by bytes transmitted in sessions that contain events that
meet the query criteria. If a network is excluded, it is excluded from all results.
•
Destination IP Address Ranking
Returns destination IP addresses. Ranked by either: number of sessions with that destination IP address
or by bytes transmitted in sessions that contain events that meet the query criteria.
•
Source Port Ranking
Returns source ports. Ranked by either: number of sessions with that source port or by bytes transmitted
in sessions that contain events that meet the query criteria.
Destination Port Ranking
•
Returns destination ports. Ranked by either: number of sessions with that destination port or by bytes
transmitted in sessions that contain events that meet the query criteria.
Protocol Ranking
•
Returns most used protocols. Ranked by either: number of sessions with that protocol or by bytes
transmitted in sessions that contain events that meet the query criteria.
User Guide for Cisco Security MARS Local Controller
20-6
Chapter 20
Queries and Reports
78-17020-01