Centralized Firewall Management Administration Guide

Table of Contents

Creating a Rule for Firewall Reports with Custom Categories

Firewall report can be generated only for firewalls with an advanced license.

You can add a report rule at Tenant level only.

To create a firewall report rule with custom categories

  1. Navigate to Manager View | Home > Reports > Rules page.
  2. Click the Add icon.
  3. Select the Reporting And Analytics > Firewall Logs > Custom as a report type.
  4. Click Next.
  5. Enter basic information.

    1. Enter a unique Report Name to identify in the list.

    2. Add a Description for the report. This is optional.
    3. Select the Run Type:

      • Select Scheduled to generate the report automatically at a specific time interval, and configure the following:

        • Select the Delivery Interval: Daily, Weekly, or Monthly.

          For Daily delivery interval: No additional configuration is required. The report is generated once every day.

          For Weekly delivery interval:

          • Select the Weekly Report Day, which is the day of the week on which the report will be generated.
          • Select the Start Day of the week to define the first day of the reporting period.
          • The report covers data for 7 days only, starting from the configured Start Day of the week.

          For Monthly delivery interval: Select the Monthly report Date, which is the day of the month (1–31) on which the report will be generated. The report covers data for the entire preceding month.

        • Select the Report Data Time Zone. The time zone set here is used to fetch report data.
        • Select the Schedule Time at which the report will be generated.
      • Select On-Demand to generate the report manually as and when needed, and configure the following:

        • Set the Time Period by selecting the time unit from the dropdown and adjusting the slider to define the data range for the report.
        • Select the Report Data Time Zone. The time zone set here is used to fetch report data.
    4. Set the Delivery Type.

      You can select both options.

      Archive By default, Archive is selected. The report is stored under Saved Reports.
      Email

      The report is generated in PDF format and sent to the email address defined in the Email Destination field.

      Reports (PDF files) exceeding 10 MB cannot be attached to email notifications. You can download reports exceeding 10 MB from Saved Reports.

    5. Enter the following information if you select Delivery Type as Email or both.

      • Select the Email Destination to receive the reports.

        Administrator By default, Administrator is selected. The report is sent to the administrator's email address.
        AdhocUser Select AdhocUser to add recipients other than the administrator.

        If AdhocUser is selected, enter the recipients' email addresses in the Email ID field. Use a semicolon to separate multiple addresses.

      • Enable Blind Carbon Copy Recipients (bcc) to send a blind copy of the report email to additional recipients.
      • Enter Email Subject.
      • Enter Email Body if you want to include any additional information about the report.
      • Enable Zip Report to receive the compressed report in the email.
    6. Click Advance Settings to expand the section (Security, Branding & Contact) and configure the following tabs:

      • Security tab — enable Password Protect to restrict access to the generated PDF report.

        Enter and confirm the password.

      • Branding tab — configure the following:

        • Enable Use Custom Logo to display a custom logo in your reports. Click or drag a file to upload, or select an existing logo from the Select a Logo dropdown.

          Only PNG images are supported. Maximum file size: 2 MB. Recommended dimensions: 200×60 px.

        • Enable Custom Partner Details to display custom partner information in the PDF report. Enter the Partner Name and About Partner description.

          If left blank, the default partner name and description will appear in the PDF report.

      • Contact & Identity tab — configure the following:

        • Enable Contact Information and enter the Email and Phone to display on the report.

          If left blank, the default contact information will appear in the PDF report.

        • Enable Prepared By and enter the Name to display in the Prepared By section of the report.

          If left blank, the default prepared by name will appear in the PDF report.

        • Enable Include Tenant Name to include the tenant name in the report. This option is enabled by default.
  6. Click Next.
  7. Setup rule section.

    You can add multiple sections with Session Logs and Predefined filters.

    1. Enter a Section title.

    2. Edit the Scope to change to tenant, group, or device.

      The scope selector option is available only on custom reports from the Manager View and not from the Firewall View.

    3. Add the filters in one of the following ways:

      Add a filter from Session Logs filters.

      1. Select the Representation Type to visualize the data.

        Time Series Chart

        Data visualization chart representing data points at successive intervals of time. Each point on the chart corresponds to the number of data points or Total of selected item(s) at a time-point. The horizontal axis (x-axis) of the chart shows increments of time. The vertical axis (y-axis) shows the selected item(s) data points. A set of time series charts can help identify a trend quickly or spot an outlier or analyze a series of peaks and valleys for comparative analysis.

        You can use the drop down to select your data points. The data points are divided into 3 different categories i.e. Distinct Data Points, Data Points and Aggregate Data Points.

        General recommendations:

        • Select an item that is not part of a filter criterion.
        • Select items for which y-axis magnitude is comparable, or create separate charts with different y-axis scales.
        Data Table

        A tabular representation of resultant data after:

        • Applying one or more filter(s) criteria on network traffic flow logs.
        • Grouped on identical data points of the selected column(s) as a grouping criterion.
        • Aggregated values are calculated by applying a grouping criterion. The data table helps in analyzing filtered and grouped flow logs.

        This allows you to generate a report where the selected item values will be represented in a tabular manner. You have to make the appropriate selections from the list of Grouping Criterion and Aggregated Criterion to get the desired report. For example, you want a weekly report of users accessing high risk application where along with user name you need total number of connections, data send, total data transferred and total threat. To generate this report, you need to create custom filter to filter out all high risk applications and use data table custom report to generate the desired report.

        You can also choose the Number of Rows of data that you want in the report.

        For example, filter flow logs for an application category and group filtered flow logs on users and application columns. Analyze the grouped data to get bytes transferred for a unique pair of users and applications. General recommendations: Select item(s) from the Time Series chart data select or that is not part of a filter criterion. Select item for which vertical axis (y-axis) magnitude is comparable, or create separate charts with different y-axis scales. Select grouping column(s) that are not part of the filtering criterion in the data table.

        You can select a maximum of 6 columns from the Grouping Criterion and Aggregated Criterion list.

      2. Select the Time Series Data from the drop-down menu if Time Series Chart is selected.

        • A minimum of one data-point should be selected.
        • You can select and add multiple criteria from the drop-down menu.

        • The selected item values will be plotted in a Time Series chart. Each point on the chart corresponds to the number of data points of selected item(s) at a time-point.
      3. Define the following parameters if Data Table is selected

        1. Specify the maximum Number of rows in the grouped data table published in the PDF report.

          You can set this value between 10 to 500. The default value is 10.

        2. Specify data table column(s) as a Grouping Criterion. The data table will be grouped on identical values of selected column(s).

          You can select and add multiple criteria from the drop-down menu.

        3. Specify criterion used for aggregating values while applying grouping criterion on the data table.

          You can select and add multiple criteria from the drop-down menu.

      4. Enable Show Representation to see the sample representation based on the parameters selected.

      Add a filter from Predefined filters.

    4. Select a filter and do one of the following:

      • Scroll down and click Add Section to add more sections.

      • Click Next to view representation of the selected filters.

        At least one filter should be selected under each section. Incomplete sections are indicated with Need Input. You can either add the filter(s) or delete the section to proceed to next.

  8. Click Next to Review.
  9. Review report details and click Finish.

    A success message is displayed. The newly created report is displayed on the page.

You can also create a report rule for a firewall in the Firewall View | Home > Reports > Rules page. The procedure for creating scheduled reports in the Firewall View is similar to creating a report rule in the Manager View.