Cisco Cisco Firepower Management Center 4000

Page of 1844
 
4-29
FireSIGHT System User Guide
 
Chapter 4      Using the Context Explorer
  Understanding the Context Explorer
Hover your pointer over any part of the graph to view more detailed information. Click any part of the 
graph to filter or drill down on that information.
Tip
To constrain the graph so it displays only countries receiving files, hover your pointer over the graph, 
then click 
Receiver
 on the toggle button that appears. Click 
Sender
 to return to the default view. Note that 
navigating away from the Context Explorer also returns the graph to the default Sender view.
This graph draws data primarily from the File Events table.
Understanding the URL Information Section
License: 
FireSIGHT or URL Filtering
Supported Devices: 
feature dependent
Supported Defense Centers: 
feature dependent
The URL Information section of the Context Explorer contains three interactive bar graphs that display 
an overall picture of URLs with which hosts on your monitored network are exchanging data: traffic and 
unique connections associated with URLs, sorted by individual URL, URL category, and URL 
reputation. You cannot filter on URL information.
Note
If you filter on intrusion event information, the entire URL Information Section is hidden. 
Note that you must have a URL Filtering license and enable URL Filtering for URL filtering graphs to 
include URL category and reputation data. Note also that neither the DC500 Defense Center nor Series 2 
devices support URL filtering by reputation and category, so the DC500 Defense Center cannot display 
this data and Series 2 devices do not detect it. See 
.
For more information on the graphs in the URL Information section, see the following topics:
  •
  •
  •