You can configure the following settings for displaying the events table:
To configure the settings for displaying the events table:
This will open a window for configuring how the events table is displayed.
The following settings are available for viewing:
For an event that is not an incident – date and time of event registration. For an incident – date and time of registration of the first event included in the incident. In the table, you can view the date together with the time, or just the date or time by itself. To select the information to display, select the check boxes opposite the Date and/or Time settings.
For an event that is not an incident, this is the date and time when the event last occurred. It may contain the date and time of event registration, or the date and time when the event regenerate counter value increased if the conditions for event registration were repeated during the event regenerate timeout. The value of the regenerate counter is displayed in the Total appearances column. For an incident, this is the latest date and time of last occurrence of events that are part of the incident. Just like with the Start column, you can view the date together with the time, or just the date or time by itself.
Header defined for the event type.
This icon corresponds to the importance level of an event or incident.
Address of the source of network packets (the abbreviated names for display in table cells are specified in parentheses):
Address of the destination of network packets (the abbreviated names for display in table cells are specified in parentheses):
Application layer protocol that was being monitored when the application registered the event.
This icon corresponds to the technology that was used to register the event.
For an event that is not an incident, this is the value of the regenerate counter after the event is registered within the event regenerate timeout. A value greater than 1 means that the conditions for event registration were repeated N – 1 times. The value 1 is displayed for the incident in this column.
Unique ID of the registered event or incident.
This icon corresponds to the status of an event or incident.
Description specified for the event type.
For an event that is not an incident, this is the date and time when the Resolved status was assigned, or the date and time of the event regenerate timeout. For an incident, this is the latest date and time of the end of events that are part of the incident. Just like with the Start column, you can view the date together with the time, or just the date or time by itself.
For an event that is not an incident, this is the name of the Process Control rule or Intrusion Detection rule whose triggering caused the registration of the event. For an incident, this is the name of the correlation rule whose triggering caused the registration of the incident.
Monitoring point whose traffic invoked registration of the event.
Numerical code assigned to the event type.
This is a selection of icons that you can set for any event or incident so that you can easily find events and incidents based on a criterion that is not in the table.
For the Start, Last seen and End columns, you can also change the order in which the date and time are displayed. For the Source and Destination columns, you can change the order of the addresses of the senders and recipients of network packets. To do so, select the value that you want to move to the left or right in the table and use the buttons containing an image of the up or down arrows.
The selected columns will be displayed in the Events section in the table in the order you specified.
Page top