SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285 by Todd Lammle & Alex Tatistcheff & John Gay

SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285 by Todd Lammle & Alex Tatistcheff & John Gay

Author:Todd Lammle & Alex Tatistcheff & John Gay [Lammle, Todd]
Language: eng
Format: azw3
ISBN: 9781119155041
Publisher: Wiley
Published: 2015-10-13T04:00:00+00:00


Figure 6.48 Reviewed status

Figure 6.49 shows a portion of the search page where you can also search by name for events reviewed by a particular user or search for all reviewed events by using a * in the Reviewed By search field.

Figure 6.49 Reviewed By search

Placing an event into Reviewed status removes it from intrusion event workflows for all users!

Okay, once events have been placed into Reviewed status, you can view them two ways. One is to use the Reviewed By search and the other is to select Analysis ➢ Intrusions ➢ Reviewed Events. Figure 6.50 shows this is actually just a shortcut to loading the Reviewed By * search, as you can see if you expand the Edit Search link on the left.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.