Cisco Cisco Firepower Management Center 4000
4-3
FireSIGHT System User Guide
Chapter 4 Using the Context Explorer
Understanding the Context Explorer
•
•
•
For information on how to configure the Context Explorer as a whole, see the following topics:
•
•
•
•
For information on configuring and using Context Explorer filters, see the following topics:
•
•
•
•
Understanding the Traffic and Intrusion Event Counts Time Graph
License:
FireSIGHT
At the top of the Context Explorer is a line chart of traffic and intrusion events over time. The X-axis
plots time intervals (which range from five minutes to one month, depending on the selected time
window). The Y-axis plots traffic in kilobytes (blue line) and intrusion event count (red line).
plots time intervals (which range from five minutes to one month, depending on the selected time
window). The Y-axis plots traffic in kilobytes (blue line) and intrusion event count (red line).
Note that the smallest X-axis interval is five minutes. To accommodate this, the system will round the
beginning and ending points in your selected time range down to the nearest five-minute interval.
beginning and ending points in your selected time range down to the nearest five-minute interval.
By default, this section shows all network traffic and all generated intrusion events for the selected time
range. If you apply filters, the chart changes to display only traffic and intrusion events associated with
the criteria specified in the filters. For example, filtering on the
range. If you apply filters, the chart changes to display only traffic and intrusion events associated with
the criteria specified in the filters. For example, filtering on the
OS Name
of
Windows
causes the time
graph to display only traffic and events associated with hosts using Windows operating systems.
If you filter the Context Explorer on intrusion event data (such as a
Priority
of
High
), the blue Traffic line
is hidden to allow greater focus on intrusion events alone.
You can hover your pointer over any point on the graph lines to view exact information about traffic and
event counts. Hovering your pointer over one of the colored lines also brings that line to the forefront of
the graph, providing clearer context.
event counts. Hovering your pointer over one of the colored lines also brings that line to the forefront of
the graph, providing clearer context.