Cisco Cisco Firepower Management Center 4000

Page of 1844
 
4-11
FireSIGHT System User Guide
 
Chapter 4      Using the Context Explorer
  Understanding the Context Explorer
To configure the Application Information section focus:
Access: 
Admin/Any Security Analyst
Step 1
Select 
Analysis > Context Explorer
.
The Context Explorer appears.
Step 2
Hover your pointer over the 
Application Protocol Information
 section. (Note that if you previously changed 
this setting in the same Context Explorer session, the section title may appear as 
Client Application 
Information
 or 
Web Application Information
 instead.)
The section option buttons appear at the upper right.
Step 3
Click 
Application Protocol
Client Application
, or 
Web Application
.
The Application Information section refreshes according to the option you selected.
Note
If you navigate away from the Context Explorer, this section reverts to its default state 
(Application Protocol).
Viewing the Traffic by Risk/Business Relevance and Application Graph
License: 
FireSIGHT
The Traffic by Risk/Business Relevance and Application graph, in donut form, displays a proportional 
representation of application traffic detected on your monitored network, arranged by the applications’ 
estimated risk (the default) or estimated business relevance. The inner ring divides by estimated 
risk/business relevance level (such as 
Medium
 or 
High
), while the outer ring further divides that data by 
specific application (such as 
SSH
 or 
NetBIOS
). Scarcely detected applications are grouped under 
Other
.
Note that this graph reflects all available data regardless of date and time constraints. If you change the 
explorer time range, the graph does not change.
Hover your pointer over any part of the graph to view more detailed information. Click any part of the 
graph to filter or drill down on that information.