27.11.2012 Views

IronPort - daily management guide - AsyncOS 7.6.1

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Email Security Monitor Pages<br />

2-26<br />

Cisco <strong>IronPort</strong> <strong>AsyncOS</strong> 7.6 for Email Daily Management Guide<br />

Chapter 2 Using Email Security Monitor<br />

In the Matches by Internal User section, you can click the name of a user to view that internal user’s<br />

(email address) Internal User details page (see Internal User Details, page 2-22).<br />

Figure 2-25 Content Filters Page<br />

The Outbreak Filters Page<br />

The Outbreak Filters page shows the current status and configuration of Outbreak Filters on your Cisco<br />

<strong>IronPort</strong> appliance as well as information about recent outbreaks and messages quarantined due to<br />

Outbreak Filters. You can use this page to monitor your defense against targeted virus, scam, and<br />

phishing attacks.<br />

The Threats By Type section shows the different types of threat messages received by the appliance. The<br />

Threat Summary section shows a breakdown of the messages by Virus, Phish, and Scam.<br />

The Past Year Outbreak Summary lists global as well as local outbreaks over the past year, allowing you<br />

to compare local network trends to global trends. The listing of global outbreaks is a superset of all<br />

outbreaks, both viral and non-viral, whereas local outbreaks are limited to virus outbreaks that have<br />

affected your Cisco <strong>IronPort</strong> appliance. Local outbreak data does not include non-viral threats. Global<br />

outbreak data represents all outbreaks detected by the Cisco <strong>IronPort</strong> Threat Operations Center which<br />

exceeded the currently configured threshold for the outbreak quarantine. Local outbreak data represents<br />

all virus outbreaks detected on this appliance which exceeded the currently configured threshold for the<br />

outbreak quarantine. The Total Local Protection Time is always based on the difference between when<br />

each virus outbreak was detected by the Cisco <strong>IronPort</strong> Threat Operations Center and the release of an<br />

anti-virus signature by a major vendor. Note that not every global outbreak affects your Cisco <strong>IronPort</strong><br />

appliance. A value of “--” indicates either a protection time does not exist, or the signature times were<br />

not available from the anti-virus vendors (some vendors may not report signature times). This does not<br />

indicate a protection time of zero, rather it means that the information required to calculate the protection<br />

time is not available.<br />

OL-25138-01

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!