McAfee® Host Intrusion Prevention 6.1 Product Guide

Maintenance

 

Running reports

IPS Event Summary by Target

Use this report to view IPS events per host. Details include:

Initial View

Level 1 Drill Down

Level 2 Drill Down

 

 

 

 

 

 

„

Host Name >

„

Host Name

„

OS User

„

Event Count

„

Signature >

„

Reaction

 

 

„

Count

„

Process

 

 

 

 

„

Source IP

 

 

 

 

„

Incident Time

 

 

 

 

„

Recording Time

 

 

 

 

„

Severity Level

 

 

 

 

„

Event description

 

 

 

 

„

Advanced details

 

 

 

 

 

 

8

Filters on signature, recording time, severity level, OS user, reaction, process, and source IP.

Network Intrusion Summary by Source IP

Use this report to view network intrusion events per source IP. Details include:

Initial View

Level 1 Drill Down

Level 2 Drill Down

 

 

 

 

 

 

„

Source IP >

„

Source IP

„

OS User

„

Event Count

„

Signature Name >

„

Reaction

 

 

„

Count

„

Process

 

 

 

 

„

Node name

 

 

 

 

„

Source IP

 

 

 

 

„

Incident Time

 

 

 

 

„

Recording Time

 

 

 

 

„

Severity Level

 

 

 

 

„

Event description

 

 

 

 

„

Advanced details

 

 

 

 

 

 

Filters on source IP, signature, OS user, reaction, recording time, severity level, and host name.

127

Page 127
Image 127
McAfee 6.1 manual IPS Event Summary by Target, Network Intrusion Summary by Source IP, Signature