How are 'Bytes' counted in ACC and traffic logs?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

How are 'Bytes' counted in ACC and traffic logs?

L2 Linker

Hi All,

One of our customers has blocked the 'Music' category in URL Filtering but when we filter the 'Music' Category in ACC, it shows total bytes for the last 7 days as 5 GB.

 

So what do bytes really represent? Why does it show 5 GB when the category is blocked? 

Please explain this in detail.

Regards,
Hiren

5 REPLIES 5

Cyber Elite
Cyber Elite

Hi @Hiren_Patel

 

Bytes are counted whenever packets traverse the firewall, they represent bytes of data

 

If you're seeing 5GB, the question should be: how is music passing through if it is blocked? maybe they forgot to enable the profile on a security policy

Did they enable the policy recently? if it's only been enabled for a few days, they may need to wait for the next full week before there will no longer be any connections counted towards the week 

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L0 Member

I have a similar question about the Network Activity ACC for Source and Destination Activity sorted by "Bytes".  The problem I have with these views is they seem to be showing sessions that were still open during the "Time" filter as opposed to having been created during the specified time.    Let's say we selected "Last Hour".  In my experience we may see the Source IP Activity ACC wiget show a source at the top of the list with a large byte count for 1 session that was open for months (and was still open in the "Last Hour".  I asked it to show me stuff going on the last hour, not a session that opened months ago.  Is this not what we should expect?

@EdKulb,

That would be due to the session closing within the last hour. The ACC tab simply reads the logs within the last hour; it doesn't matter if that session started within the last hour as long as the log was generated within the last hour. 

This is completely normal and expected behavior. 

Makes perfect sence, thanks.

It is completely reasonable to consult more attractive and completely free content.

  • 5425 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!