New features and improvements in PT ISIM proView Sensor / netView Sensor version 2.4
1. New features
Incident display modes
In the new version of PT ISIM proView Sensor / netView Sensor, the Incidents page has been fully upgraded. You can now view incidents in different modes: • In live mode, which is intended for estimating the current state of the analyzed system. This mode displays only unclosed incidents. In live mode, you can view data as a summary and as a table. • In "All incidents" mode, which enables you to view all incidents recorded in PT ISIM proView Sensor / netView Sensor and search for specific incidents using filtering by parameters. In this mode, you can download a list of incidents in CSV format and create an incident report. Instructions on how to manage incidents are provided in the PT ISIM proView Sensor / netView Sensor Operator Guide.
2. Improvements
Downloading large PCAP files
In previous versions, a copy of traffic related to events or incidents can be downloaded only as an archive containing PCAP files for the appropriate period. Depending on the type of traffic and the number and size of the PCAP files, such a download may take a while and increase the system load. In this version, if the size of an archive with PCAP files exceeds 500 MB, a text file with a link to download the PCAP files from the PT ISIM proView Sensor / netView Sensor server is downloaded instead. You can download such PCAP files by following the link from the file or using file retrieval tools (for example, wget). For details, see the PT ISIM proView Sensor / netView Sensor Operator Guide.
List of available fields in notification templates
In PT ISIM proView Sensor / netView Sensor, you can change the templates of incident notifications that the product sends over syslog or by email. In the templates, you can use incident parameters as variables to insert real values of these parameters in notifications. To facilitate the search for all available parameters, the new version of PT ISIM proView Sensor / netView Sensor contains the file /opt/ptisim/etc/fullview/httpapi.conf.d/incidents-notify-fields.yaml, which includes the names of all incident parameters in the format that can be used in the templates. For details, see the PT ISIM proView Sensor / netView Sensor Administrator Guide.
Displaying event time
In PT ISIM proView Sensor / netView Sensor 2.3 and earlier, events are displayed with an accuracy of seconds. In PT ISIM proView Sensor / netView Sensor 2.4, events are displayed with an accuracy of milliseconds. Such accuracy makes it possible to distinguish events from one another when multiple events occur in one second. Updating the product to version 2.4 initiates the process of migrating events to the new timestamp format. For details, see the PT ISIM proView Sensor / netView Sensor Administrator Guide.
Saving data in history mode after an update
In previous versions, the history mode has a limitation: only the data received after the latest product update is available. In version 2.4, there is no such limitation. The node diagram can now display data for a point in time preceding the product update to version 2.4.
For additional details, see the PT ISIM proView Sensor / netView Sensor Release Notes.
|