Firewall Management Reports and Analytics for Unified Management

Table of Contents

Sources

Interface‑based Monitor > Overview > Live Report > Data Usage reports differ from session or flow‑based Monitor > Details > Sources reports.

  • The Monitor > Overview > Live Report > Data Usage reports calculate usage based on bytes received (Rx) and transmitted (Tx) on a firewall's physical interface. These values represent raw interface counters.
  • The Monitor > Details > Sources reports are flow‑based and include only traffic associated with successfully established, session‑tracked connections.

This report displays the number of connections based on IP address of the source. You can filter on the source type listed in the drop-down list. You can also find the data in the form of a Pie Chart as well as a Graph.

Click on Details, below each report, to go to the details page of the Source report. You can also view the page by navigating to Details > Sources. The top of the Details page shows a graphical representation of the selected By Metric data over a time period.

The bottom of the page has a table that shows information such as name of the source IP addresses, connections and total data transferred. The rest of the columns of the table can be selected from the Column Config button at the top of the page. The total information of each column can be seen at the extreme bottom of the page.

You can filter the information according to the IP version by selecting from IPv4, IPv6 or Both.

The Search button at the top of the Firewall View | Monitor > Details > Sources page allows you to search multiple IP addresses at the same time using the CIDR method. For example, you can search 142.250.0.0/16 to see all the subnets under the series 142.250. You can also search 142.250.196.0/24 to see all the subnets under the series 142.250.196.