WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide WatchGuard Firebox System 4.6 User Guide

watchguard.com
from watchguard.com More from this publisher
13.07.2015 Views

Scheduling and running reportsDeleting a filterTo remove a filter from the list of available filters, highlight the filter. Click Remove.This command removes the .ftr file from the report-defs directory.Applying a filterEach report can use only one filter. To apply a filter, open the report properties. FromHistorical Reports:1 Select the report for which you would like to apply a filter. Click Edit.2 Use the Filter drop list to select a filter.Only filters created using the Filters dialog box appear in the Filter drop list. For moreinformation, see “Creating a new filter” on page 113.3 Click OK.The new report properties are saved to the ReportName.rpt file in the report-defs directory. Thefilter will be applied the next time the report is run.Scheduling and running reportsWatchGuard offers two methods to run reports: manually at any time or scheduledautomatically using the LiveSecurity Event Processor.Scheduling a reportYou can schedule the LiveSecurity Event Processor to automatically generate reportsabout network activity. To schedule reports:1 Right-click the LiveSecurity Event Processor desktop tray icon. Select Open LogCenter.2 Click the Reports tab.3 Select a report to schedule.4 Select a time interval.For a custom interval, select Custom and then enter the interval in hours.5 Select the first date and time the report should run.The report will run automatically at the time selected and then at each selected intervalthereafter.6 Click OK.Manually running a reportAt any time, you can run one or more reports using Historical Reports. FromHistorical Reports:1 Enable the checkbox next to each report you would like to generate.2 Click Run.114

Report sections and consolidated sectionsReport sections and consolidated sectionsYou can use Historical Reports to build a report that includes one or more sections.Each section represents a discrete type of information or network activity.You can consolidate certain sections to summarize particular types of information.Consolidated Sections summarize the activity of all devices being monitored as agroup as opposed to individual devices.Report sections can be divided into two basic types:• Summary – Report sections that rank information by bandwidth or connections.• Detailed – Report sections that display all activity with no summary graphs orranking.The following is a listing of the different types of report sections and consolidatedsections.Firebox StatisticsA summary of statistics on one or more log files for a single Firebox.Authentication DetailA detailed list of authenticated users sorted by connection time. Fields include:authenticated user, host, start date of authenticated session, start time ofauthenticated session, end time of authenticated session, and duration of session.Time Summary – Packet FilteredA table, and optionally a graph, of all accepted connections distributed along userdefinedintervals and sorted by time. If you chose the entire log file or specific timeparameters, the default time interval is daily. Otherwise, the time interval is basedon your selection.Host Summary – Packet FilteredA table, and optionally a graph, of internal and external hosts passing trafficthrough the Firebox sorted either by bytes transferred or number of connections.Service SummaryA table, and optionally a graph, of traffic for each service sorted by connectioncount.Session Summary – Packet FilteredA table, and optionally a graph, of the top incoming and outgoing sessions, sortedeither by byte count or number of connections. The format of the session is: client -> server : service. If the connection is proxied, the service is represented in allcapital letters. If the connection is packet filtered, Historical Reports attempts toresolve the server port to a table to represent the service name. If resolution fails,Historical Reports displays the port number.Time Summary – Proxied TrafficA table, and optionally a graph, of all accepted connections distributed along userdefinedintervals and sorted by time. If you chose the entire log file or specific timeparameters, the default time interval is daily. Otherwise, the time interval is basedon your selection.User Guide 115

Report sections and consolidated sectionsReport sections and consolidated sectionsYou can use Historical Reports to build a report that includes one or more sections.Each section represents a discrete type of information or network activity.You can consolidate certain sections to summarize particular types of information.Consolidated Sections summarize the activity of all devices being monitored as agroup as opposed to individual devices.Report sections can be divided into two basic types:• Summary – Report sections that rank information by bandwidth or connections.• Detailed – Report sections that display all activity with no summary graphs orranking.The following is a listing of the different types of report sections and consolidatedsections.<strong>Firebox</strong> StatisticsA summary of statistics on one or more log files for a single <strong>Firebox</strong>.Authentication DetailA detailed list of authenticated users sorted by connection time. Fields include:authenticated user, host, start date of authenticated session, start time ofauthenticated session, end time of authenticated session, and duration of session.Time Summary – Packet FilteredA table, and optionally a graph, of all accepted connections distributed along userdefinedintervals and sorted by time. If you chose the entire log file or specific timeparameters, the default time interval is daily. Otherwise, the time interval is basedon your selection.Host Summary – Packet FilteredA table, and optionally a graph, of internal and external hosts passing trafficthrough the <strong>Firebox</strong> sorted either by bytes transferred or number of connections.Service SummaryA table, and optionally a graph, of traffic for each service sorted by connectioncount.Session Summary – Packet FilteredA table, and optionally a graph, of the top incoming and outgoing sessions, sortedeither by byte count or number of connections. The format of the session is: client -> server : service. If the connection is proxied, the service is represented in allcapital letters. If the connection is packet filtered, Historical Reports attempts toresolve the server port to a table to represent the service name. If resolution fails,Historical Reports displays the port number.Time Summary – Proxied TrafficA table, and optionally a graph, of all accepted connections distributed along userdefinedintervals and sorted by time. If you chose the entire log file or specific timeparameters, the default time interval is daily. Otherwise, the time interval is basedon your selection.<strong>User</strong> <strong>Guide</strong> 115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!