Kaspersky Industrial CyberSecurity for Networks

Viewing events associated with a link

March 22, 2024

ID 181444

You can view the events associated with the links on the network interactions map. When events are loaded, they are automatically filtered based on the IDs of events associated with the link, and based on the time period.

You can use the following methods to load events associated with links:

The application loads no more than 200 events associated with a link. If there are more events, the events with the highest severity and with the latest time of occurrence are selected first.

To view events associated with a link:

  1. On the network interactions map, select a link (except a link in which one of the sides of communication is a consolidated node of unknown devices).

    The details area appears in the right part of the web interface window.

  2. Depending on which events you want to load, click one of the following buttons (the buttons are available if there are events associated with the link):
    • Show events – if you want to view events with any status.
    • Show unprocessed events – if you want to view events with the New or In progress status.
  3. If more than 200 events associated with the link were registered during the time period defined on the network interactions map, a warning about the large number of events is displayed. In the prompt window, confirm whether you want to load events with the highest severity levels.

The Events section opens. The events table applies a filter based on the IDs of events and the time period defined on the network interactions map. If you loaded events by using the Show unprocessed events button, events are additionally filtered by the Status column.

To view events associated with links of nodes in collapsed groups:

  1. On the network interactions map, select the link showing interactions with nodes in the collapsed group.

    The details area appears in the right part of the web interface window. The Total links: <number> settings group contains a list of the maximum severities of events in links to nodes of the collapsed group. For each severity level, the number of links with this severity is displayed. Only the severity levels of links to nodes of the collapsed group are displayed. If there are links that are not associated with any event, No events is displayed with the number of such links.

  2. Load events using the To events link in the row containing the relevant severity.

    You can load the following events:

    • For the High severity level, events associated with links that have High severity are loaded.
    • For the Medium severity level, events associated with links that have Medium or High severities are loaded.
    • For the Low severity level, events associated with links that have Low, Medium, or High severities are loaded.
  3. If more than 200 events associated with the links that have the selected severities were registered during the time period defined on the network interactions map, a warning about the large number of events is displayed. In the prompt window, confirm whether you want to load events with the highest severity levels.

The Events section opens. The events table applies a filter based on the IDs of events and the time period defined on the network interactions map.

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.