User's Guide

Table Of Contents
Forensics
235
In case of AP based threats, client is the device that is associated with the primary device (AP). In case of
Client based threats, client is the primary device.
When you select an event seen under Forensics, you can view the details of the devices participating in
the event. You can also view the quarantine status of these devices
To view the participating device details and quarantine status, do the following.
1.
Go to Forensics.
2.
Select the location for which you want to view the threats. The AP and client based threats for the
selected location are displayed.
3.
Click the time hyperlink next to Select duration to define the time duration for which you want to view
the threats. The AP related threats and client related threats for this duration are displayed.
4.
Click the type of threat under AP related threats or client related threats. All events falling under this
threat category that have occurred during the selected time duration are displayed.
5.
Select an event row and view the participating devices in the participating devices section seen below
the event list. The following fields are seen under Participating Devices.
Field
Description
AP
AP name
Client
Client name
Association Start Time
Start time when the primary device associates with
the participating device.
Association End Time
Time of end of association of primary device with
the participating device.
Quarantine Status
Indicates if the device has been quarantined.
Quarantined indicates that the device is
quarantined. Not quarantined indicates that
the
device is not quarantined.
Quarantine status is a
hyperlink. Depending on the status, you can see the
quarantine details or the reason for not being
quarantined on clicking the status hyperlink.
Locate Participating Device
You can locate the participating devices for which the AP related or client related threats have occurred.
1.
Go to Forensics.
2.
Select the location for which you want to view the threats. The AP and client based threats for the
selected location are displayed.
3.
Click the time hyperlink next to Select duration to define the time duration for which you want to view
the threats. The AP related threats and client related threats for this duration are displayed.
4.
Click the type of threat under AP related threats or client related threats. All events falling under this
threat category that have occurred during the selected time duration are displayed.
5.
Select an event row and view the participating devices in the participating devices section seen below
the event list.
6.
Under Participating Devices, click the Locate hyperlink for the device to locate. The location of the
selected device at the selected time is displayed in the Map View. This means that the device is
shown on the floor map that is attached to the location where the threat has been detected. Click the
Switch to Proximity View hyperlink to view the distance of the located device from the locating
device. This link toggles between Switch to Map View and Switch to Proximity View depending on
what view is currently visible to you.