Report Descriptions and Configuration

Bytes by Period Firewall Report

ID: bytes-by-period

Chart: histogram

This report shows the number of bytes aggregated in configurable time periods.

Parameters

period

This parameter controls the time period over which the bytes are aggregated.

Defaults to 1d.

Traffic's Volume by Rule Firewall Report

ID: bytes-by-rule

Chart: bars

This report shows the volume of data logged by each rule.

This report doesn't have any parameters.

Bytes by Timeslot Firewall Report

ID: bytes-by-timeslot

Chart: histogram

This report shows the volume of traffic distributed by timeslots (hours of the day, days of the week, etc.) that passed (or were denied) by your firewall.

Parameters

timeslot

This parameter controls the length of the timeslot over which the packets are aggregated. Use 1h for ‘hours of the day’ or 1d for ‘days of the week’.

Defaults to 1h.

Top Bytes per From-IP Report

ID: bytesperfrom

Chart: bars

This report lists the IP addresses sending the highest data volume.

Parameters

ips_to_show

This parameter controls the number of sending IP adresses to display in the report.

Defaults to 10.

Top Bytes per From-IP per Port Report

ID: bytesperfromperport

Chart: bars

This report lists the volume we were asked to receive per source IP per source port.

Parameters

ips_to_show

This parameter controls the number of sending IP adresses to display in the report.

Defaults to 10.

ports_to_show

This parameter controls the number of source ports to display in the report.

Defaults to 10.

Top Bytes per To-ip Report

ID: bytesperto

Chart: bars

This report lists the IP addresses for which we were asked to sent the highest data volume to.

Parameters

ips_to_show

This parameter controls the number of receiving IP adresses to display in the report.

Defaults to 10.

Top Bytes per destination IP per Port Report

ID: bytespertoperport

Chart: bars

This report lists the volume were asked to receive per destination IP per port.

Parameters

ips_to_show

This parameter controls the number of receiving IP adresses to display in the report.

Defaults to 10.

ports_to_show

This parameter controls the number of ports to display in the report.

Defaults to 10.

Top blocked tcp packets per source IP per destination port Report

ID: deniedtcpperport

Chart: bars

This report lists the destination ports for which we blocked the highest tcp data volume, along with the sending ip adresses

Parameters

ips_to_show

This parameter controls the number of sending IP adresses to display in the report.

Defaults to 10.

ports_to_show

This parameter controls the number of destination ports to display in the report.

Defaults to 10.

Packets by Period Firewall Report

ID: pkt-by-period

Chart: histogram

This report shows the number of packets logged by the firewall aggregated in configurable time period.

Parameters

period

This parameter controls the time period over which the packets are aggregated.

Defaults to 1d.

Packets by Rule Firewall Report

ID: pkt-by-rule

Chart: bars

This report shows the number of packets logged by the firewall for each rules.

This report doesn't have any parameters.

Packets by Timeslot Firewall Report

ID: pkt-by-timeslot

Chart: histogram

This report shows the number of packets distributed by timeslots (hours of the day, days of the week, etc.).

Parameters

timeslot

This parameter controls the length of the timeslot over which the packets are aggregated. Use 1h for ‘hours of the day’ or 1d for ‘days of the week’.

Defaults to 1h.

Packet Summary Firewall Report

ID: pkt-summary

Chart: None

This report shows some general statistics about the number of packets logged by your firewall.

This report doesn't have any parameters.

Top Volume to Destination by Source Firewall Report

ID: top-bytes-dst-by-src

Chart: None

This report will show for a number of source IP addresses that sent the most volume of traffic, the list of destination (destination IP and destination port).

Parameters

src_to_show

This parameter controls the number of source IP adresses to display in the report.

Defaults to 15.

dst_to_show

This parameter controls the number of destination (IP address and port) to display for each source IP.

Defaults to 20.

Top Volume to Destination by Source Firewall Report

ID: top-bytes-src-by-dst

Chart: None

This report will show for each destination (destination IP and port) the list of source IPs that sent the most volume.

Parameters

dst_to_show

This parameter controls the number of destination (IP address and port) to display in the report.

Defaults to 15.

src_to_show

This parameter controls the number of source IP adresses that will be displayed for each destination.

Defaults to 20.

Top Messages Firewall Report

ID: top-msg

Chart: bars

This report shows the top messages (IDS alerts or others) generated by the firewall.

Parameters

msgs_to_show

This parameter controls the number of messages to show in the report.

Top Messages Firewall Report

ID: top-dst-by-msg

Chart: None

This report shows the top destination IPs that are the target of the messages (IDS alerts or others) generated by the firewall.

Parameters

msgs_to_show

This parameter controls the number of messages to show in the report.

ips_to_show

This parameter controls the number of destination IPS to list with each message.

Top Messages Firewall Report

ID: top-src-by-msg

Chart: None

This report shows the top source IPs that are at the origin of the messages (IDS alerts or others) generated by the firewall.

Parameters

msgs_to_show

This parameter controls the number of messages to show in the report.

ips_to_show

This parameter controls the number of source IPS to list with each message.

Top Packets by Source IP Report

ID: top-pkt-by-src

Chart: bars

This report lists the IP addresses that were listed as source in the most packets.

Parameters

ips_to_show

This parameter controls the number of source IP adresses to display in the report.

Defaults to 10.

Top Packets by Destination IP Report

ID: top-pkt-by-dst

Chart: bars

This report lists the IP addresses that were listed as destination in the most packets.

Parameters

ips_to_show

This parameter controls the number of destination IP adresses to display in the report.

Defaults to 10.

Top Packets Destination by Source Firewall Report

ID: top-pkt-dst-by-src

Chart: None

This report will show for a number of source IP addresses that sent the most packets, the list of destination (destination IP and destination port).

Parameters

src_to_show

This parameter controls the number of source IP adresses to display in the report.

Defaults to 15.

dst_to_show

This parameter controls the number of destination (IP address and port) to display for each source IP.

Defaults to 20.

Top Packets Source by Destination Firewall Report

ID: top-pkt-src-by-dst

Chart: None

This report will show for each destination (destination IP and port) the list of source IPs that sent the most packets.

Parameters

dst_to_show

This parameter controls the number of destination (IP address and port) to display in the report.

Defaults to 15.

src_to_show

This parameter controls the number of source IP adresses that will be displayed for each destination.

Defaults to 20.

Volume Summary Firewall Report

ID: vol-summary

Chart: None

This report shows some general statistics about the size of the packets logged by your firewall.

This report doesn't have any parameters.