18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 218: Attacks by<br />

Service window<br />

About the Attacks<br />

by Service window<br />

In this area, you can:<br />

Chapter 18: Monitoring<br />

Viewing IPS attack and system event summaries<br />

• Change the displayed statistics based on time period by selecting different<br />

options in the Display summary statistics for drop-down list. The range <strong>of</strong><br />

options vary depending on the <strong>Sidewinder</strong> <strong>G2</strong>’s uptime.<br />

• View audit data for any system event or attack category by clicking the<br />

magnifying glass .<br />

• View a snapshot <strong>of</strong> all attacks listed by service by clicking<br />

Attacks by Service. See “About the Attacks by Service window” on page<br />

523 for more information.<br />

• View and save attack audit data by clicking Most Recent IPS Attacks.<br />

• View an individual audit record by double-clicking that audit event’s row.<br />

See “About the Audit Record window” on page 524 for more information.<br />

Use this area <strong>of</strong> the dashboard to monitor the following:<br />

• System events by severity — Lists system audit events according to<br />

severity<br />

• Attacks by severity — Lists audit attack events according to severity<br />

• Attacks by service — Lists audit attack events according to service<br />

• Most recent IPS attacks — Displays the audit events for recent attacks<br />

Note: Use the Admin Console’s IPS Attack Responses and System Event<br />

Responses to determine how <strong>Sidewinder</strong> <strong>G2</strong> reacts to different audit events. For<br />

more information, see the “IPS Attack and System Event Responses” chapter.<br />

This window displays audit <strong>of</strong> suspect traffic. Information provided includes:<br />

• Name — Name <strong>of</strong> the service being attacked<br />

• Count — Number <strong>of</strong> attack instances<br />

On this window, you can:<br />

• Click Refresh to update the information.<br />

• Select a service and click Show Audit to see the audit output. You can also<br />

view the audit by clicking the magnifying glass on the main window.<br />

• Click Close to return to the main window.<br />

523

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!