Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Table of Contents
minLevel2
maxLevel2
typeflat

Purpose

Firewall Monitoring Activeboard allows you to analyze and monitor firewall traffic logs from different angles. In this Activeboard you will be able to:

  • Get data insights and filter them.

  • Track the traffic volume and actions.

  • Have access to Traffic Reputation heatmaps.

  • Compare the connections.

  • Get details about the most used Firewall rules.

  • Analyze denied firewall traffic and most rejected source IPs.

Pre-requisites

To use the Firewall Monitoring Activeboard, you must have the following data sources available on your domain:

Open Firewall Monitoring

Once you have installed the Activeboard, you can access the Activeboard in the following ways:

Go to Exchange in the navigation pane and look for the Activeboard you want to open. Click Open.

Go to Activeboards in the navigation paneand use the filter to open the Activeboard you downloaded.

Info

Know more about Activeboards

Refer to Manage and filter Activeboards article to know how to work with Activeboards.

Exploring the Activeboard

When opening the Firewall Monitoring Activeboard, the following info displays:

Note

Load data takes too long

Sometimes some widgets take time to upload the data, it is possible to speed up the process by creating aggregation tasks. Refer to Aggregation tasks article to learn how to do it.

Rw ui expands macro
Rw expand
titleClick here to see the details

Widget

Details

Filters for data insights

Last 100 Firewall Events

Traffic Volume by Application (last day)

Traffic Action Distribution

Traffic Activity Over Time by Action

Traffic Activity Over Time by Protocol

Source IP List

Bandwith

Destination IP List

Firewall Actions (Allow vs. Deny)

Top Source IPs (by bytes)

Source IP by:

  • Connections

  • Total KB

Destinations IP by:

  • Connections

  • Total KB

Top Talkers by Connections

Top Talkers by Data Transfer

Most Used Firewall Rules - Occurrence

Most Used Firewall Rules - Detail

Most Used Firewall Rules

Most rejected Source IPs (>1000)

Most Rejected Source IPs