- play_arrow What's New for JSA Users
- play_arrow Capabilities in your JSA product
- play_arrow Dashboard Management
- Dashboard Management
- Default Dashboards
- Custom Dashboards
- Creating a Custom Dashboard
- Using the Dashboard to Investigate Log or Network Activity
- Configuring Dashboard Chart Types
- Removing Dashboard Items
- Detaching a Dashboard Item
- Renaming a Dashboard
- Deleting a Dashboard
- Managing System Notifications
- Adding Search-based Dashboard Items to the Add Items List
- play_arrow Offense Management
- play_arrow Log Activity Investigation
- play_arrow Network Activity Monitoring
- play_arrow Asset Management
- play_arrow Chart Management
- play_arrow Event and Flow Searches
- play_arrow Custom Event and Flow Properties
- play_arrow Rules
- play_arrow Historical Correlation
- play_arrow Juniper Networks X-Force Integration
- play_arrow Report Management
ON THIS PAGE
Events
Use the Events page to further investigate specific events to determine the root cause of an issue and work to resolve it.
The Events page displays a table of the events that contributed to a specific offense and a Time Series chart that shows the number of events sorted by date. You can filter these events to suit your needs.
Investigating Events
The Events graph on the offense details page displays the number of events that occurred at a given time within the last 7 active days.
From the offenses page, click on an offense in the offense table to open the details page.
Tip:Use the scrubber bar at the top of the Events graph to zoom in on specific times and event spikes.
Click View Events to see a list of events that contributed to the offense and investigate event details.
To configure the number of events returned in your filter results, click the arrows in the Result Limit indicator.
To configure the number of events displayed in the table, click the Items per page drop-down at the bottom of the table.
To sort the events table in ascending or descending order by an attribute, click the appropriate table heading.
Click on an event to see more details about that event. You can also click on a log source, source IP, or destination IP for specific information on that source or destination.
Click Update events to refresh the events results.
Tip:You can copy and paste the URL from your browser to share the events page, including all filters and configuration options.
Filtering Events
Filter the Events page to display only the specific events you want to investigate.
As you apply filters, the events table displays only the events that meet your filter criteria.
You can copy and paste the URL from your browser to share the events page, including all filters and configuration options.
To apply a filter, click any of the following categories to see filtering options for that category:
Event Time
Magnitude
Log Source Name
Category
Source IP
Source Port
Destination IP
Destination Port
Event Name
User
To include only events with specific attributes, select that attribute in the filters list. To exclude events with specific attributes, click the vertical ellipsis icon next to the attribute, and click Apply IS NOT Filter.
Tip:You can right-click on a Log Source, Source IP, Destination IP, Category, or Username in the events table and quickly apply an IS or IS NOT filter to the events.
To sort the events table in ascending or descending order by an attribute, click the appropriate table heading.
To clear individual filters, click the close icon [x] on the filter indicator. To clear all filters, click Clear filters.
Click Update events to refresh the events results.