•
|
Debug/Informational Events—Connection setup/tear down
|
•
|
User-events—Administrative access, single sign-on activity, user logins, content filtering details
|
•
|
Firewall Rule/Policy Events—Access to and from particular IP:Port combinations, also identifiable by time
|
•
|
Interesting-content at the Network or Application Layer—Port-scans, SYN floods, DPI or AF signature/policy hits
|
The following is an example of the process of distributed event detection and replay: