Using the Realtime Console
Figure 11-13
In this example, many events are observed to be active almost all of the time. This usually
indicates a high rate of false positives.
Figure 11-14
trailing events and also a much less dense occurrence of any one event.
Figure 11-14
Figure 11-15
11-12 Enterasys IPS Analysis and Reporting Guide
Realtime EventSummary (48-Hour Time line)
shows a more common output on a well-tuned Dragon Network Sensor. Notice the
Realtime EventSummary (Well-Tuned)
Realtime EventSummary (IPS Events)
Legacy Reporting
Need help?
Do you have a question about the Intrusion Prevention System and is the answer not in the manual?
Questions and answers