18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 19: Auditing and Reporting<br />

Generating reports using the Admin Console<br />

558<br />

Generating exportable reports<br />

The <strong>Sidewinder</strong> <strong>G2</strong> allows you to create exportable data files from the report<br />

data your site generates. This allows you to transfer files from the <strong>Sidewinder</strong><br />

<strong>G2</strong>, and load them into a database or spreadsheet application. You can export<br />

data via FTP, e-mail, a diskette, or a DAT.<br />

The report data that you can export from the <strong>Sidewinder</strong> <strong>G2</strong> is located in the<br />

/var/log/export_data directory unless you specify otherwise. The exportable<br />

files include:<br />

• probe_attempt<br />

• acl_denied<br />

• traffic<br />

• root_access<br />

• udb_action<br />

Note: These data files have dates added to them that correspond to the dates the<br />

files were created. Each file contains exportable <strong>Sidewinder</strong> <strong>G2</strong> audit data that<br />

corresponds to what is summarized in the respective <strong>Sidewinder</strong> <strong>G2</strong> reports.<br />

Enter the following commands at the UNIX prompt to generate exportable data<br />

files:<br />

• To create an exportable file in /var/log/export_data based on the previous<br />

day’s audit information:<br />

gen_reports -e -r all<br />

This generates all reports in separate files.<br />

• To create an exportable file in /var/log/export_data based on the latest<br />

(current) traffic audit information:<br />

gen_reports -f filename -r traffic<br />

This generates all traffic reports in separate files with the specified filename<br />

added to the front instead <strong>of</strong> the cf reports timestamp.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!