- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-28-2022 10:58 AM
I am trying to understand how to view threats, malicious IPs, etc over time. For instance in the ACC tab I understand one can view threats, threat source IPs etc. I am not seeing how to view trends, for example if we want to see if there has been an increase in traffic from a certain country or threats from a certain source IP. I would like to be able to view a report and see if there were increases in a certain time frame. I am only seeing total count, a break down of information over a time would be useful. I would appreciate any help, thanks.
03-01-2022 07:36 AM
You can generate a custom report of source country activity and add the date as criteria along with count to get a basic understanding of network increases it that's something that you are looking for. Historical trend information is generally something that I would offload to an external SIEM however (IE: Graylog/Splunk) to build detailed reporting dashboards however instead of the firewall's built-in reporting capability.
03-01-2022 07:36 AM
You can generate a custom report of source country activity and add the date as criteria along with count to get a basic understanding of network increases it that's something that you are looking for. Historical trend information is generally something that I would offload to an external SIEM however (IE: Graylog/Splunk) to build detailed reporting dashboards however instead of the firewall's built-in reporting capability.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!