Viewing network activity details for a SmartVision alert

Prev Next

When you investigate a SmartVision alert, the Network Activity Details panel displays information about critical network activity that involved the attacking host from five minutes before the alert until five minutes after.

SmartVision_events_NetworkActivityDetails.png

You can filter the list of related network activity as follows:

Time

You can view activity that occurred up to five minutes before the SmartVision alert, activity that occurred up to five minutes after the event, or both.

Event type

You can filter related network activity by protocol type or file type within the layer 4 and layer 7 traffic flows.

Column

You can filter related network activity on any combination of columns:

  • Event type

  • Timestamp

  • Source (attacker) IP address and port number

  • Destination (victim) IP address and port number

  • Details

Prerequisites

To view the network activity details for a SmartVision alert:
  1. Log in to the appliance Web UI and choose Alerts > SmartVision.

  2. Click the arrow at the left side of the SmartVision alert group you want to explore.

  3. Click the arrow at the left side of the individual SmartVision alert you want to explore. The Summary panel is expanded by default.

  4. Click Network Activity Details. The panel lists network activity that involved the attacking host from five minutes before the alert until five minutes after.

  5. To filter the list by activity timestamp, select the appropriate toggle:

    • Select Before Events to view only the activity that occurred up to five minutes before the SmartVision alert.

    • Select After Events to view only the activity that occurred up to five minutes after the SmartVision alert.

    • Select All Events to stop filtering the activity by timestamp.

  6. To filter the list by event type, click the colored circle for that event type.

  7. To filter the list on any combination of columns, enter match strings in the column headings.