Chapter 20
Queries and Reports
Destination IP
•
Specifies that the constraints entered are the session endpoints.
•
Specifies that the constraints entered are the destination as appearing at the source.
•
No constraint is placed on the source IP addresses.
•
Any one IP address, only useful for queries in tandem with the same variable.
•
IP addresses present on devices in the system or user entered dotted quads.
•
The range of addresses between two dotted quads.
•
Topologically valid networks.
•
The hosts and reporting devices present in the system.
Service
•
No constraint is placed on the source or destination ports or protocol.
•
Any one set of destination port and protocol, only useful for queries in tandem with the same variable.
•
Services on the database.
Event Types
•
No constraint on the event type.
•
Events that have been merged into types.
•
Groups of event types.
Device
•
78-17020-01
Post NAT destination addresses
Pre NAT destination addresses
ANY
Variables
IP addresses
IP ranges
Networks
Devices
ANY
Service variables
Defined services
ANY
Event types
Event type groups
Devices
User Guide for Cisco Security MARS Local Controller
Queries
20-11