19.15. Intrusion DetectionΒΆ

The diagnostics provide three tabs.

The Overview tab provides general information about memory usage and packet statistics.

The Logs tab shows fast log matches for rules, mainly drop/reject events.

The Event Log shows detailed information for each matched flow with protocol and application data associated with a flow or event. Source and destination IPs can show reverse DNS entry on hover, as long as the VT AIR can resolve the IP.

Intrusion Detection Diagnostics Intrusion Detection Diagnostics Intrusion Detection Diagnostics Intrusion Detection Diagnostics Intrusion Detection Diagnostics