Contents
lii
User Guide for Cisco Security Manager 4.4
OL-28826-01
Event Details Pane 66-24
Preparing for Event Management 66-24
Ensuring Time Synchronization 66-25
Configuring ASA and FWSM Devices for Event Management 66-25
Configuring IPS Devices for Event Management 66-26
Managing the Event Manager Service 66-27
Starting, Stopping, and Configuring the Event Manager Service 66-27
Monitoring the Event Manager Service 66-28
Selecting Devices to Monitor 66-31
Monitoring Event Data Store Disk Space Usage 66-31
Archiving or Backing Up and Restoring the Event Data Store 66-32
Using Event Viewer 66-33
Using Event Views 66-33
Opening Views 66-34
Floating and Arranging Views 66-34
Customizing the Event Table Appearance 66-35
Switching Between Source/Destination IP Addresses and Host Object Names 66-36
Configuring Color Rules for a View 66-36
Creating Custom Views 66-37
Editing a Custom View Name or Description 66-38
Switching Between Real-Time and Historical Views 66-38
Saving Views 66-38
Deleting Custom Views 66-39
Filtering and Querying Events 66-39
Selecting the Time Range for Events 66-39
Using the Time Slider with Filtering 66-40
Refreshing the Event Table 66-40
Creating Column-Based Filters 66-41
Filtering Based on a Specific Event’s Values 66-43
Filtering on a Text String 66-44
Clearing Filters 66-44
Performing Operations on Specific Events 66-45
Event Context (Right-Click) Menu 66-45
Examining Details of a Single Event 66-47
Copying Event Records 66-48
Saving Events to a File 66-48
Looking Up a Security Manager Policy from Event Viewer 66-48
Examples of Event Analysis 66-50
Help Desk: User Access To a Server Is Blocked By the Firewall 66-50