| Advantage of analyzing Firewall logs:
|
Firewall logs reveal a lot of information on the nature of traffic coming in and going out of the firewall, allows you to plan your bandwidth requirement based on the bandwidth usage accross the firewalls. Analyzing these firewall traffic logs is vital to understand network and bandwidth usage and plays an important role in business risk assessment.
| Analyzed Firewall Log Reports: FireWall Logs/4.FutureSystem
|
FutureSystem Firewall Log Analysis..
Reporting of Future System Firewall Logs..
LogQuest VF can verify, analyze and generate report for Future System Firewall logs.You need to collect Future System Firewall Logs and then verify in LogQuest VF.
Report based on the file: FireWall Logs/4.FutureSystem/firelog_test1_20050201.log Pre-defined Log Format: Standard Log/WELF Format Date report was created: 13th October 2007
a)Report Conditions are: Condition(1)=Data: firewall,Column: <25>id,Logic: Contain,Rule: Count,Mode:Single Condition(2)=Data: *,Column: Src, Logic: Contain,Rule: Count,Mode: Single Condition(3)=Data: http, Column: proto,Logic: Contain,Rule: Count,Mode: Single Condition(4)=Data: *,Column: sent,Logic: Contain,Rule: Count,Mode: Single
Report
|
|
b)Report Conditions are: Condition(1)=Data: firewall,Column: <25>id,Logic: Contain,Rule: Count,Mode: Single Conditioin(2)=Data: 220.95.222.10, Column: dst,Logic: Contain,Rule: Count,Mode: Single Condition(3)= Data: *,Column: sent,Logic: Contain,Rule: Count,Mode: Single Condition(4)=Data: *,Column: rcvd,Logic: Contain,Rule: Count,Mode: Single
Report
|
|
c)Report Conditions are: Condition(1)=Data: firewall,Column: <25>id,Logic: Contain,Rule: Count,Mode:Single Condition(2)=Data: 203.248.159.164, Column: src,Logic: Contain,Rule: Count,Mode: Single Condition(3)=Data: *,Column: sent,Logic: Contain,Rule: Count,Mode: Single Condition(4)=Data: *,Column: rcvd,Logic: Contain,Rule: Count,
Mode: Single
Report
|
|
d)Report Conditions are: Condition(1)=Data: firewall,Column: <25>id,Logic: Contain,Rule: Count,Mode: Single Condition(2)=Data: *,Column: src,
Logic: Contain,Rule: Count,Mode: Single Condition(3)=Data: *,Column: dst,Logic: Contain,Rule: Count,Mode: Single Condition(4)=
Data: SPD Rule:1,NAT Rule:Not apply,Column: msg,Logic: Contain,Rule: Count, Mode: Single
Report
|
|
e)Report Conditions are: Condition(1)=Data: firewall,Column: <25>id,Logic: Contain,Rule: Count,Reporting mode: Single Condition(2)=Data: *, Column: src,Logic: Contain,Rule: Count,Reporting mode: Single Condition(3)=Data: *,Column: proto,Logic: Contain,Rule: Count,Reporting mode: Single Condition(4)=Data: 5,Column: pri,Logic: Contain,Rule: Count, Reporting mode: Single Condition(5)=Data: ,Column: msg,Logic: Contain,Rule: Count,Reporting mode: Single
Report 1
|
|
Report 2
|
|
|