18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Generating<br />

reports using the<br />

Admin Console<br />

Chapter 19: Auditing and Reporting<br />

Generating reports using the Admin Console<br />

The <strong>Sidewinder</strong> <strong>G2</strong> Reports window in the Admin Console allows you to<br />

generate commonly used reports based on pre-defined report formats, such as<br />

administrative user connections, network probe attempts, traffic information,<br />

and active rule (ACL) usage, to name a few.<br />

The report information that is displayed is pulled from the audit database.<br />

When audit events are generated, information relevant to each event (such as<br />

a date and time, process identification information, user identity, and address<br />

information) is automatically appended to the audit information to help an<br />

administrator identify and categorize the audit data that is stored. If the report is<br />

comprised <strong>of</strong> numerous areas, the information in the report is appropriately<br />

categorized for ease <strong>of</strong> viewing.<br />

For example, if you run the traffic report, you will receive a summary <strong>of</strong> the<br />

various types <strong>of</strong> proxy traffic as follows: service, source host, destination, and<br />

user. If you want to view only traffic generated by users, you could instead run<br />

the user_traffic report to view only a summary <strong>of</strong> all user traffic.<br />

You can further refine your results by running the user_activity report and<br />

specify a single user whose activity you want to view. When you run the<br />

user_activity report, you will receive a detailed report <strong>of</strong> all <strong>of</strong> that user’s<br />

system activity, organized into sections (such as general traffic, root access<br />

attempts, rule violations, and so on). The information contained in a report will<br />

depend on the time frame you specify.<br />

Note: To view reports using a command line interface, see the cf_reports man<br />

page.<br />

To generate reports using the Admin Console, select Audit and Reports ><br />

Reports. The following window appears.<br />

Important: You must enable the auditdbd server before you can generate reports.<br />

See “Enabling and disabling servers” on page 65 for information on enabling the<br />

auditdbd server.<br />

551

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!