190 Monitoring
About incident and event data
Viewing incident and event data
This section describes the following topics:
Viewing incident and event data
■
Adjusting the view
■
Examining incident data
■
Examining event data
■
The Network Security console displays incident and event data in the following:
Incidents tab: Displays both active and idle incidents. When you select an
■
incident, Events At Selected Incident in the lower pane displays information
about the related events.
Devices tab: Displays the topology tree. When you select an object in the
■
topology tree, the Network Security console displays related information in
the right pane, including a link to security incidents that are currently
active on that object.
The Incidents tab provides a multi-level view of both incidents and events.
Incidents are groups of multiple related base events. Base events are the
representation of individual occurrences, either suspicious or operational. The
sensors notify the software or appliance node of any suspicious actions or
occurrences that might warrant a response, such as a probe. Symantec Network