beautypg.com

Displaying attack/virus/ddos snapshot list, Configuration guide – H3C Technologies H3C SecCenter IPS Manager User Manual

Page 47

background image

41

Displaying attack/virus/DDoS snapshot list

The system presents attack, virus, and DDoS events not only through graphs but also lists. The

attack/virus/DDoS event snapshot lists present you the attack/virus/DDoS attack events that occurred

during the last hour in order of time, with the most recent event at the top. Each event record includes the

event’s time, device IP address, source IP address, destination IP address, event description, protocol,

source port, and destination port, helping you track the latest security status of the network in an intuitive

way.
The IPS Manager provides filters for you to choose information of interest. For more information about

filters, see “

Managing filters

.”

Configuration guide

From the navigation tree of the IPS management component, select Attack Snapshot List, Virus Snapshot

List, or DDoS Current Event List under Realtime Monitoring to enter the attack snapshot list page, the virus

snapshot list page, or the DDoS current event list page, as shown in

Figure 40

,

Figure 41

, and

Figure 42

.

Figure 40 Attack event snapshot list

Figure 41 Virus event snapshot list

Table 42

describes the query options of the attack/virus snapshot list.

Table 43

describes the fields of the

attack/virus snapshot list, and

Table 44

describes the fields of the DDoS current event list.