для Cisco Cisco FirePOWER Appliance 8270
18-20
FireSIGHT System User Guide
Chapter 18 Working with Intrusion Events
Using the Packet View
To display the packet view:
Access:
Admin/Intrusion Admin
Table 18-5
Packet View Actions
To...
You can...
modify the date and time
range in the packet views
range in the packet views
find more information in
learn more about the
information displayed in
the packet view
information displayed in
the packet view
find more information in:
•
•
•
•
•
•
add an event to the
clipboard so you can
transfer it to the incidents
at a later time
clipboard so you can
transfer it to the incidents
at a later time
either:
•
click
Copy
to copy the event whose packet you are viewing
•
click
Copy All
to copy all the events whose packets you previously selected
The clipboard stores up to 25,000 events per user. For more information on the clipboard, see
delete an event from the
event database
event database
either:
•
click
Delete
to delete the event whose packet you are viewing
•
click
Delete All
to delete all the events whose packets you previously selected
mark an event reviewed to
remove it from event views,
but not the event database.
remove it from event views,
but not the event database.
either:
•
click
Review
to review the event whose packet you are viewing
•
click
Review All
to review all the events whose packets you previously selected
For more information, see
. Note that reviewed events
continue to be included in the event statistics on the Intrusion Event Statistics page.
download a local copy of
the packet (a packet capture
file in libpcap format) that
triggered the event
the packet (a packet capture
file in libpcap format) that
triggered the event
either:
•
click
Download Packet
to save a copy of the captured packet for the event you are viewing
•
click
Download All Packets
to save copies of the captured packets for all the events whose
packets you previously selected
The captured packet is saved in libpcap format. This format is used by several popular protocol
analyzers.
analyzers.
Note that you cannot download a portscan packet because single portscan events are based on
multiple packets; however, the portscan view provides all usable packet information. See
multiple packets; however, the portscan view provides all usable packet information. See
for more information.
Note that you must have at least 15% available disk space in order to download.
expand or collapse a page
section
section
click the arrow next to the section.