When you investigate a SmartVision alert, the Network Activity Details panel displays information about critical network activity that involved the attacking host from five minutes before the alert until five minutes after.

You can filter the list of related network activity as follows:
Time
You can view activity that occurred up to five minutes before the SmartVision alert, activity that occurred up to five minutes after the event, or both.
Event type
You can filter related network activity by protocol type or file type within the layer 4 and layer 7 traffic flows.
Column
You can filter related network activity on any combination of columns:
Event type
Timestamp
Source (attacker) IP address and port number
Destination (victim) IP address and port number
Details
Prerequisites
Log in to the appliance Web UI and choose Alerts > SmartVision.
Click the arrow at the left side of the SmartVision alert group you want to explore.
Click the arrow at the left side of the individual SmartVision alert you want to explore. The Summary panel is expanded by default.
Click Network Activity Details. The panel lists network activity that involved the attacking host from five minutes before the alert until five minutes after.
To filter the list by activity timestamp, select the appropriate toggle:
Select Before Events to view only the activity that occurred up to five minutes before the SmartVision alert.
Select After Events to view only the activity that occurred up to five minutes after the SmartVision alert.
Select All Events to stop filtering the activity by timestamp.
To filter the list by event type, click the colored circle for that event type.
To filter the list on any combination of columns, enter match strings in the column headings.