Cisco Cisco Firepower Management Center 4000

Seite von 1844
 
4-3
FireSIGHT System User Guide
 
Chapter 4      Using the Context Explorer
  Understanding the Context Explorer
  •
  •
  •
For information on how to configure the Context Explorer as a whole, see the following topics:
  •
  •
  •
  •
For information on configuring and using Context Explorer filters, see the following topics:
  •
  •
  •
  •
Understanding the Traffic and Intrusion Event Counts Time Graph
License: 
FireSIGHT
At the top of the Context Explorer is a line chart of traffic and intrusion events over time. The X-axis 
plots time intervals (which range from five minutes to one month, depending on the selected time 
window). The Y-axis plots traffic in kilobytes (blue line) and intrusion event count (red line).
Note that the smallest X-axis interval is five minutes. To accommodate this, the system will round the 
beginning and ending points in your selected time range down to the nearest five-minute interval.
By default, this section shows all network traffic and all generated intrusion events for the selected time 
range. If you apply filters, the chart changes to display only traffic and intrusion events associated with 
the criteria specified in the filters. For example, filtering on the 
OS Name
 of 
Windows
 causes the time 
graph to display only traffic and events associated with hosts using Windows operating systems.
If you filter the Context Explorer on intrusion event data (such as a 
Priority
 of 
High
), the blue Traffic line 
is hidden to allow greater focus on intrusion events alone.
You can hover your pointer over any point on the graph lines to view exact information about traffic and 
event counts. Hovering your pointer over one of the colored lines also brings that line to the forefront of 
the graph, providing clearer context.