Viewing network isolation rule details
To view network isolation rule details:
- Select the Network traffic events section in the application web interface window.
- Select the Threat response tab.
The table of network rules is displayed.
- Select the rule for which you want to view information.
This opens a window containing information about the rule.
The window contains the following information:
- Start is the date and time when the network isolation request was sent to the NGFW solution. Corresponds to the start of processing the operation.
- End is the date and time when the NGFW solution finished processing the request and applied the rule. Corresponds to the completion of the operation.
- Status is the status of the rule. Possible values: Pending, Running, Success, Failure.
- ID is the unique ID of the rule.
- Object type is the type of the isolated object.
- Event title is the title of the NDR event that the rule was based on.
- Alerts lists alerts related to the NDR event that the rule was based on.
- Event score is the severity score of the event.
- Device is the name of the isolated device.
- Section Details:
- Device IP is the IP address of the isolated device.
- Connector name is the name of the connector that is used to connect to the NGFW solution.
Page top