In the
tab, you can see the options.Table 8-1 Analysis Tab User Interface
User Interface |
Description |
---|---|
The Analysis menu in the menu bar |
|
The Navigation Tree in the Navigation pane |
|
The toolbar buttons |
The following Top 10 dashboards are available in Sentinel and can be downloaded from the Sentinel Content page:
Top 10 Target IP Addresses
Top 10 Initiating IP Addresses
Top 10 Target Host Names
Top 10 Initiating Host Names
Top 10 Target User Names
Top 10 Initiating User Names
Top 10 Target Port Names
Top 10 Event Names
The Top 10 dashboards are enabled by default, and the following summaries are turned on to enable the Top 10 dashboards:
EventDestSummary
EventSevSummary
EventSrcSummary
If Top 10 dashboards are not needed, you can disable these summaries, or you can enable additional summaries in order to use them for reporting. If the summary service is not in use, you can disable it.
To enable or disable summaries:
In the Sentinel Control Center, go to
.Select the Summary to enable or disable and click the status (
/ ) of that summary.Select
to confirm that you want to change the status of the summary.To enable or disable EventFileRedirectSerice:
At your Sentinel machine, using text editor, open:
<install_directory>/config/das_binary.xml
For EventFileRedirectService, change the status to on or off, as appropriate. For example:
<property name="status">off</property>
Log in to the Sentinel Control Center as the Sentinel Administrator.
Go to
.Right-click
and select .