Mysql Event Table - Symantec 10521146 - Network Security 7120 Administration Manual

Administration guide
Hide thumbs Also See for 10521146 - Network Security 7120:
Table of Contents

Advertisement

334 SQL reference
Using MySQL tables
Table B-3
MySQL Incident Table
Field Name
Type
severity
integer
state
integer
time
integer
type
varchar(129)
viewed
integer

MySQL event table

Table B-4
MySQL Event Table
Field Name
atkaction
atkproc
atkuser
class
Description
Indicates the severity of the best event.
Indicates the state of this incident.
Indicates the time that the incident record was
last updated.
Indicates the type of the best event.
Indicates the marked status of this incident.
The following table describes the structure of the table that Symantec Network
Security uses to export event data to a MySQL database:
Type
Description
integer
Indicates the attempted action.
text
Indicates the process name of the attacker, or
blank if not applicable.
varchar(255)
Indicates the username of the attacker, or blank if
not applicable.
varchar(33)
Indicates the event class.
Notes
Valid values are 1-10
1 = active (currently being
monitored by the AF)
0 = closed (archived to the
db)
Standard UNIX time format
(seconds since 1970 GMT)
0 = Not yet marked by a
Network Security console
user.
1 = Marked by a Network
Security console user, and
unchanged since.
2 = Marked by a Network
Security console user, but
has changed since.
Notes
sniffer - for
security events
generic - for
operational events,
etc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network security

Table of Contents