Methods and systems for extracting,
processing, displaying, and analyzing events that are associated with one or more threats are provided. According to one embodiment,
threat information, including information from one or more of firewall logs and historical
threat logs, is maintained in a
database. Information regarding
threat filtering parameters, including one or more of types of threats to be extracted from the
database, parameters of the threats, network-level details of the threats, a time interval of detection of the threats and source-destination details of the threats, is received. Information regarding threats matching the threat filtering parameters are extracted from the
database and is presented in a form of an interactive historical graph. Responsive to receiving from a user an indication regarding a selected subset of time in which to
zoom into for further details, a
list of threats within the selected subset is presented in tabular form.