You can add a filter of your choice. This is specially useful if you are unable to find a specific attribute in the security tables. To add a filter of your choice:
- From the Domain drop-down list in the left pane, select the root admin domain.
- Click Add Filter.
- Enter the values in the following fields:
- Filter On — Select a core attribute from the drop-down list.
- Value — Choose the specific value from the drop-down list.
Note
- In the Dashboard page, if you directly click a hyperlink on any security monitor, you are directed to the Threat Explorer page with the core attribute and admin domain already set. You can then choose to add more filter criteria. Example: A click in the Top Applications(NTBA) security monitor displays the Threat Explorer page with the core attribute Application Name, for example, HTTP. You can select the time duration and network flow from the options in the right hand corner.
- If you click on the attack details in the Top Attack Countries and the Top Target Countries monitors, you are redirected to the Attack Log page with the filter attribute for the Country already set.
- To investigate details on an attack name, for example,
MALWARE: Malicious PDF File transfer Detected, click
Add Filter, select this attack name and click
Save. The refreshed page displays details based on both primary and secondary filters applied.
Add Filters .png)
Remember
If you remove the primary filter, the secondary filter becomes the primary criterion and vice-versa.
- Click
View Attacks to navigate to the
Attack Log page and investigate based on filtered criteria.
Note
When Connections or Bytes are selected, you can view the attacks only when a single filter is applied. If secondary filter is also applied, the option to view attack is disabled.