Firewall Management Reports and Analytics for Unified Management

Table of Contents

Up Time Report

Up Time Report is a real-time view of the uptime, downtime, and NSM/Firewall Management connectivity status of the firewall. The report tracks three states: Uptime, Offline, and Disconnected. The data can be viewed in graph as well as grid view.

State Description
Uptime

The firewall is powered on and connected to NSM/Firewall Management.

Measured as the total duration of successful communication with NSM/Firewall Management.

Offline

The firewall was powered off and unreachable.

Duration is calculated retrospectively once the firewall reconnects to NSM/Firewall Management.

Displayed as Disconnected until the retrospective analysis is complete.

Disconnected

The firewall is powered on, but cannot communicate with NSM/Firewall Management.

Possible causes: network issue, configuration change, or ISP outage.

Also displayed temporarily for firewalls that were Offline, until NSM/Firewall Management completes the retrospective downtime analysis.

Uptime reports are based on heartbeat messages received from the firewall. If heartbeats stop, the firewall appears disconnected. NSM/Firewall Management can confirm whether the firewall is disconnected or down only after receiving a heartbeat following the interruption.

You can use the Time Slider to adjust the time duration and the Custom button to customize the dates. The slider allows you to view the report from a duration of 1 hour to 30 days. If you select a time range of 1, 6, 12, or 24 hours, the report is shown in the interval of 1 hour. If you select a time range of 3, 7, or 30 days, the report is shown in the interval of 24 hours.

Use the All Firewalls drop-down list to filter the report for a specific firewall or to view aggregated data for all firewalls. Use the All Status drop-down list to filter by status: Downtime, Disconnected, Offline (downtime and disconnected events combined), or Any Status.

The summary bar displays the count of Firewalls Down and Firewalls Disconnected. Click either count to apply the corresponding filter. The average uptime, downtime, and disconnection duration are shown in both percentage and absolute time.

The report is organized into the following tabs:

  • Affected Firewalls — Lists firewalls that have at least one downtime or disconnected event. Hover over an entry to view the firewall name, device group, uptime duration and percentage, disconnected duration, and offline duration. Click the filter icon to apply a filter for that firewall. This tab is available only at the tenant and group levels.
  • Timeline — Displays aggregated data by time period. Expand a time period to view a list of firewalls and their uptime, disconnected, and offline details.
  • Outages — Lists all downtime and disconnected events. Each entry shows the Type, Firewall, Start Time, End Time, and Duration. A summary at the top shows the total number of outage, downtime, and disconnected events.

You can also export the data in CSV, PDF, and Excel formats using the Export button and refresh the page using the Refresh button. Use the Chart or Data Grid option to customize whether the report displays the chart, the grid, or both.

The Up Time Report is available:

  • For both Advanced and Essential License.
  • At tenant, group, and firewall levels.
  • For all Gen 8 firewalls.
  • Only on firewalls running SonicOS version 7.1.2 or later.

    If a firewall is upgraded to SonicOS 7.1.2, configure Reporting and Analytics to enable this report type according to Reinitializing Configurations for Reporting and Analytics.