
ManageEngine Firewall Analyzer :: User Guide
26
Zoho Corp.
Using the Dashboard
The Dashboard is shown when the Home tab is clicked. It is the first page you see when
you log in. You can also customize your Dashboard Views as per requirements.
Dashboard Views selection is available only in the Home tab.
Once the server has started receiving records, the Dashboard dynamically changes to
display the current statistics for each device whose log files are analyzed. The Firewall
Analyzer dashboard shows the:
• Traffic Overview Graphs
• Security Overview Graphs
• Traffic Statistics
• Security Statistics
• Basic Search
• Advanced Search
The Traffic Overview graphs shows protocol-wise distribution of traffic across each
device. At one glance, you can see the total traffic generated by each protocol group
across each device. You can also drill down from the bars in the graph to see specific
protocol usage in the Protocol Usage Report.
The Security Overview graphs shows distribution of security events like attack, virus,
port scans, etc.. generated across each device. Drill down from the bars in the graph to
see the corresponding events generated.
Firewall Analyzer will recognize only those firewall log messages which contains the
attribute denoting a port scan. Currently Firewall Analyzer recognizes the attribute
denoting a port scan for Fortigate, NetScreen & CheckPoint firewall's alone.
The Traffic Statistics table, shows the Traffic Overview graph's data in more detail,
with specific percentage values of incoming and outgoing traffic per protocol group
across each device. The Show bar lets you view the the top 5(default) / 10 / 15 or All
protocol groups, captured in the logs across the configured devices. You can click on the
Traffic IN, Traffic OUT, and Total Traffic for each protocol group of the configured device
to obtain the drill-downs of the traffic. If the
icon is displayed above the table, it
indicates that intranet's have not been configured. You need to configure intranet's if you
want to separate inbound and outbound firewall traffic.
Click the Live Syslog link is provided in Home > Traffic Statistics > Device Name
(besides the Firewall device). This will show the live syslogs information for the specific
firewall. This will give the live syslog details i.e., Source IP, Destination IP, Port and
syslog informations, provided the interfaces (i.e., eth0 etc.) should be open. In Linux the
application should be started using root user. You can apply filter on Source IP and Port
to get live syslogs received from particular IP/Port. If you click Live Syslog link, the
Firewall Analyzer - Syslog Viewer screen pops up. In the screen, on top you will find
'Receiving Syslog Packets. _ packets received' message appears. Below that there
is a Capture Filter : option with Host IP Address and Port. This capture filter will help
Commentaires sur ces manuels