Table of Contents | ||||||
---|---|---|---|---|---|---|
|
...
Purpose
Firewall Monitoring Activeboard allows you to analyze and monitor firewall traffic logs from different angles. In this Activeboard you will be able to:
Get data insights and filter them.
Track the traffic volume and actions.
Have access to Traffic Reputation heatmaps.
Compare the connections.
Get details about the most used Firewall rules.
Analyze denied firewall traffic and most rejected source IPs.
...
Pre-requisites
...
Expand | |||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| |||||||||||||||||||||||||||||||||||||||
|
Tip |
---|
This activeboard supports multitenancy. |
Prerequisites
To use this Activeboard, you must have the following data sources available on your domain:
firewall.all.traffic
learn more
Open
...
Activeboard
Once you have installed the Activeboard, you can
...
Go to Exchange in the navigation pane and look for the Activeboard you want to open. Click Open.
...
Info |
---|
Know more about Activeboards Refer to Manage and filter Activeboards article to know how to work with Activeboards. |
Exploring the Activeboard
When opening the Firewall Monitoring Activeboard, the following info displays:
...
use the Open button at the top right of the card in Exchange to access it and see the different widgets populated with the relevant data. You can also access the Activeboard area via the Navigation pane.
...
Info |
---|
Data loading takes too long? Sometimes some widgets take time to upload the data, it is possible to speed up the process by creating aggregation tasks. Refer to the Aggregation tasks article to learn how to do it. |
...
Rw expand | ||
---|---|---|
|
...
Widget
...
Details
...
Filters for data insights
...
...
Last 100 Firewall Events
...
Traffic Volume by Application (last day)
...
...
Traffic Action Distribution
...
...
Traffic Activity Over Time by Action
...
...
Traffic Activity Over Time by Protocol
...
Source IP List
...
...
Bandwith
...
...
Destination IP List
...
...
Firewall Actions (Allow vs. Deny)
...
...
Top Source IPs (by bytes)
...
...
Source IP by:
Connections
Total KB
...
...
Destinations IP by:
Connections
Total KB
...
...
Top Talkers by Connections
...
...
Top Talkers by Data Transfer
...
...
Most Used Firewall Rules - Occurrence
...
...
Most Used Firewall Rules - Detail
...
...
Most Used Firewall Rules
...
...
Most rejected Source IPs (>1000)
...
...
Use Activeboard
After installing and opening the Activeboard, you can use its widgets to visualize and monitor data. To do this, each widget offers a variety of customization and visualization options. Refer to Using widgets and Using inputs to know them all.