Kaspersky Anti Targeted Attack Platform

Table of registered NDR events

You can view the table of registered NDR events and aggregate events in the Network traffic events section.

By default, the table of registered NDR events and aggregate events is updated in real time. At the top of the table, events with the most recent last-seen date and time values are displayed.

The last-seen date and time of an NDR or aggregate event may not be the same as the date and time of its registration. For an NDR event, the last-seen date and time may be updated during the regeneration period of that event type. For an aggregate event, the last-seen date and time is updated to match the last-seen date and time of nested NDR events.

Parameters of NDR events and aggregate events are displayed in the following columns of the table:

  • Start.

    For an NDR event, the date and time when the event was registered. For an aggregate event, the date and time when the first nested event was registered. You can view the date together with the time, or just the date or time by itself. To choose the information to display, select the check boxes opposite the Date and Time settings.

  • Last seen

    For an NDR event, the last-seen date and time of the NDR event. May contain the date and time of the event registration or the date and time when the event repetition counter was incremented if the event registration conditions recurred during the regeneration period. The value of the regenerate counter is displayed in the Total appearances column. For an aggregate event, the latest last-seen date and time among events included in the aggregate event. Just like with the Start column, you can view the date together with the time, or just the date or time by itself.

  • Title.

    The title configured for the NDR event type.

  • Score.

    The calculated score for the NDR event. This numerical value determines the severity level of the NDR event. Depending on the severity level, the score can be displayed in one of the following colors:

    • Red for a High-severity event.
    • Yellow for a Medium-severity event.
    • Blue for a Low-severity event.
  • Source.

    Address of the source of network packets. You can enable or disable the display of addresses and ports of address information by using the following settings (their abbreviated names displayed in table columns are indicated in the parentheses): IP address, Port number (P), MAC address, VLAN ID (VID), and Application-level address. If additional address spaces were added to the application, you can show or hide address space names by using the Show address spaces setting when configuring the devices table.

  • Destination.

    Address of the destination of network packets. The display of address information can be configured the same way as the Source column.

  • Protocol.

    Application layer protocol for which the event was registered.

  • Technology.

    Icon corresponding to the technology used to register the NDR event.

  • Total appearances.

    For an NDR event, the value of the repetition counter after the registration of the NDR event during the regeneration period. A value greater than 1 means that the conditions for registering an NDR event recurred N – 1 times. For an aggregate event, this column displays a value of 1.

  • ID.

    Unique identifier of the registered NDR or aggregate event.

  • Application.

    Information about applications that caused the conditions for registering the NDR event. The NDR event stores information about applications received from EPP applications.

  • Application user.

    Information about the user account that started the application specified in the Application column.

  • Status.

    Icon corresponding to the status of the NDR event or aggregate event.

  • Description.

    The description specified for the NDR event type.

  • End.

    For an NDR event, the date and time when the Resolved status was assigned or the regeneration period of the NDR event. For an aggregate event, the latest resolution date and time across nested NDR events. Just like with the Start column, you can view the date together with the time, or just the date or time by itself.

  • Triggered rule.

    For an NDR event, the name of the Process Control rule or Intrusion Detection rule that, when triggered, caused the NDR event to be registered. For an aggregate event, the name of the correlation rule that, when triggered, caused the aggregate event to be registered.

  • Monitoring point.

    Monitoring point whose traffic invoked registration of the NDR event.

  • Event type.

    Numeric code assigned to the NDR event type.

  • Marker.

    A set of icons that you can assign to any NDR or aggregate event to easily find NDR or aggregate events based on a criterion that is not present in the table.

When viewing the table of network traffic events, you can configure, filter, search, and sort records and navigate to related items.