Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


Event Viewer Customization

Mar 17,2010 by alperen

image

Event Viewer combines the functionality of a browser (such as Explorer) with that of a spreadsheet (such as MS Excel) to create a collection of audit event data called a drillsheet. The drillsheet allows groups of similar audit-event records to be displayed on a single row, allowing you—quickly and easily—to detect patterns in the data.

Traditional event viewers display events in a single list. Each event fills one row in the list and each data element within an event fills one cell in the row. This display of events is appropriate when the number of events is small. When the number of alarms is large, however, or when events appear quickly, this linear display isn’t practical.

The Event Viewer groups alarms together into one row, based on similar information to both alarms. By default, the Event Viewer consolidates or collapses alarms, based on the first two field columns. For example, you might have ten alarms present in the event viewer all triggered by the same signature. Rather than listing ten different rows for each alarm, Event Viewer creates one record (row) listing the name of the alarm with a count field value of 10. Any information common to all ten alarms is listed in the record. Any information different among the ten alarms is listed as a + symbol, indicating additional information exists. You can view the additional information by expanding the record. To expand the record, simply double-click the + sign.


1094 times read

Related news

» Event Viewer
by alperen posted on Mar 17,2010
» Preference Settings
by alperen posted on Mar 17,2010
» Managing Alarms
by alperen posted on Mar 17,2010
» Configuring Event Logging (IDS version 3.1)
by admin posted on Nov 24,2008
» Signature and Alarm Management
by alperen posted on Mar 10,2010
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author