- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Custom Rule Report
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Custom Rule Report
Hello All,
I have inherited a R80.40 system and I have a few rules that are allowing more than I would like. Now I know a few Services (Ports/Protocols) that are going through I want to remove, but going through the logs and trying to weed everything out is painful. I was wondering if I could write a report for a specific rule that would show the top number of Service's (Ports/Protocols) that were going through that rule? If this is possible then I could move things to more appropriate places or black them all together and trim the fat so to speak.
Thanks,
Scott
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Depending on the rule that's being matched, it may not be possible to run a report.
The main reason being SmartEvent generally does not index connection logs from the firewall blade, only sessions (generally things that are tracked by a higher-level blade like App Control).
That said, I can think of a couple ways to do this:
- Use SmartView to export the last million logs against the relevant rule into a CSV file, where you can import to Excel or similar.
- You can also get some rough statistics in SmartView, but you'd have to scroll through the various log entries to get them to load into memory so the stats can be shown.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks a lot for the explanation. I will look into this and report back.
