Figure 47 Attack event details

Table 54 Event details query options

Option

Description

 

Select a device, a device group, or All devices from the Device drop-down list. The system

 

will display the relevant event information. All devices and device groups that are under

 

your management will appear in the drop-down list.

Device

IMPORTANT:

If you select a device group, the system will display the event information (matching the

 

 

filter) of all firewall devices in the device group in the specified statistics duration.

 

If you select a device name, the system will display the event information (matching the

 

filter) of the firewall device in the specified statistics duration.

 

 

Filter

Select a filter from the drop-down list to filter attack events.

 

 

Duration

Select the statistics duration. You can select Day, Week, or Month, or select Customize to

specify a statistics duration.

 

 

 

Time

Select the statistics time, whose value range varies with the statistics duration selected.

 

 

Event

Select an attack event type to query the specified type of attack events

 

 

Protocol

Select the attack protocol. The default is --, which means any protocol.

 

 

Severity

Select the attack severity. The default is --, which means any severity.

 

 

Src IP

Specify the attack source IP address.

 

 

Dest IP

Specify the attack destination IP address.

 

 

Dest Port

Specify the attack destination port.

 

 

Grouping by

Select a grouping mode. The system supports seven grouping modes: None, Event, Src IP,

Dest IP, Src IP and Dest IP, Dest Port, and Protocol.

 

 

 

48