Views:
Network Criteria Query Pane Fields
Section Description
Addresses & Ports It enables you to enter criteria for searching and displaying events. These options include the following:
-Src Addr - Source IP address
-Src Port - Port of the source IP address
-Dst Addr - Destination IP address
-Dst Port - Port of the destination IP address
Packet Trace Indicates if the query should locate action sets with packet trace enabled:
-All
-Events with Packet Trace
-Events without Packet Trace
VLAN ID It enables you to enter criteria for searching and displaying events based on your VLAN ID.

 

Procedure:

  1. Log in to the SMS from a client.
  2. On the top Navigation menu, click Events.
  3. On the Events screen, click Inspection Events in the Navigation pane.
  4. On the Query pane, select the triangle symbol (▶) next to Network Criteria to expand this option.
  5. In the Addresses and Ports area, enter:
    • Src Addr(s) - Source IP address
    • Src Port(s) - Port of the source IP address
    • Dst Addr(s) - Destination IP address
    • Dst Port(s) - Port of the destination IP address
  6. When searching for source or destination IP addresses, you can:
    • Enter multiple IP addresses separated by commas.
    • Enter one address or a CIDR block.
    • Exclude IP addresses in a CIDR block using the "!" symbol.
  7. Select the desired entry from the Packet Trace drop-down listings.
  8. If you want to include a VLAN ID in your search query, enter the ID in the VLAN area.
  9. Enter the number of matching rows (1 - 10,000) to list in the Display Pane. Limiting the number of rows may decrease the query processing time.
  10. Click Refresh. The returned attack events are displayed in the List pane.
  11. To save this query, click Save As. When prompted, enter a name for the query. The query will be displayed in the Saved Queries section of the Events Navigation pane. To create a new query, click Clear. The query pane will reset and clear the criteria fields.
 
 
Note: You are not required to complete all query fields. Complete only as many as you need to execute your query successfully.


Reference: SMS User Guide