• No results found

Viewing logs for allowed traffic

In document Admin Guide for Web Security Service (Page 173-178)

The Allowed Traffic report shows traffic to sites allowed by policy and by site overrides. Allowed traffic is not blocked by policy.

To view allowed traffic logs:

1. Select the Logs tab to open the Allowed Traffic view.

2. Specify the groups to include in the logs (deleted groups are displayed with the ** prefix). Select All Groups; or, to specify one or more groups:

l Click to select a single group.

l Shift-click or click and drag to select contiguous groups.

l Ctrl-click to select non-contiguous groups.

3. Select one or more dates from the last 90-day period:

-165

-WSS 4.4.0-2

l Click to select a single date.

l Shift-click or click and drag to select contiguous dates.

l Ctrl-click to select non-contiguous dates.

4. Optionally, set log filters based on the following table.

If you don’t select filtering options, the log returns all records for the specified groups and dates.

Data points

URL 1. Select the checkbox and specify a search option:

l Contains returns URL addresses containing the string in the text box.

l Does not contain returns URL addresses that don’t have the string in the text box.

l RegExp returns URL addresses typed in the form of a regular expression.

2. Type the string in the text box to be matched based on the criteria. Type a minimum of one character.

3. Specify whether the search applies to domain only, or to the domain and full path. An example of a domain ishttp://streamerapi.finance.yahoo.com

An example of a domain and path is

http:// streamerapi.finance.yahoo.com/1.0

Time 1. Select the checkbox and specify a search option:

l Between returns logs on activity that occurred within the specified time range.

l Not between returns logs on activity that occurred outside (before and after) the specified time range.

2. Enter the starting time in the first text box. For time, use the following 24-hour format:hh:mmwhere hhis from 00 to 23 andmmis from 00 to 59. Examples of valid time formats:08:00or13:30.

3. Enter the ending time in the second text box. This value must be at least one minute from the starting time. For example, if the starting time is 04:03, the ending time must be at least 04:04. If your starting and ending times are 04:04 to 04:04, no records are returned even if data exists for 04:04:22.

Data points

User 1. Select the checkbox and specify a search option:

l Contains returns logs on users whose name contains the text string you provide.

l Does not contain excludes users whose name contains the text string you provide.

l Equals returns logs on the user whose name exactly matches the text string you provide.

l Does not equal returns logs on users whose names do not exactly match the text string you provide.

2. Type a text string of up to 64 characters, the maximum length for user names, in the text box to be matched based on the criteria. Valid characters are a to z, A to Z, and 0 to 9.

IP 1. Select the checkbox and specify a search option:

l Contains returns logs on IP addresses that contain the numeric string you provide.

l Does not contain excludes IP addresses that do not contain the numeric string you provide.

l Equals returns logs on the IP address that exactly matches the numeric string you provide.

l Does not equal returns logs on IP addresses that do not exactly match the numeric string you provide.

2. Type a numeric string in the text box to be matched based on the criteria.

Valid characters are 0 to 9 and the dot separator.

Category Select the checkbox and specify the category:

l Click to select a single category.

l Shift-click or click and drag to select contiguous categories.

l Ctrl-click to select non-contiguous categories.

-167

-WSS 4.4.0-2

Data points

Search String This refers to the queries typed by users for their web searches.

Note: Most search engine results are identified, but some online searches may not be included in the results.

1. Select the checkbox to use this data point.

2. Select one search criteria:

l Contains returns logs on users whose name contains the text string you provide.

l Does not contain excludes users whose name contains the text string you provide.

l Equals returns logs on the user whose name exactly matches the text string you provide.

l Does not equal returns logs on users whose names do not exactly match the text string you provide.

3. Type a text string in the text box to be matched based on the criteria.

Size 1. Select the checkbox and specify a search option:

l Between returns logs on file sizes within the specified range.

l Not between returns logs on file sizes outside the specified range.

2. Enter the lowest size for the range and select the corresponding unit of measure.

3. Enter the highest size for the range and select the unit of measure. If the value for the lowest range is greater than the value for the highest range, the value for the highest range is ignored. The log returns data based on the lowest range of up to 1 GB in size.

Security Select one:

l All (http and https)

l Insecure pages only (http)

l Secure pages only (https)

To change the number of returned records:

1. Open the Max Results drop-down menu and select the number of records to display for the search.

Note that the Filter text box is disabled if you set the Max Results value to 200. To use the Filter box, select another Max Results value.

2. Click Search.

Matching records are displayed in tabular format.

Allowed Traffic data shown in logs

Date The date you selected for the log. If you selected multiple dates, the log allocates one row per date.

Time The time the user requested access to a site.

Group Name The group from which traffic was generated.

User Name Displays the name of the user that accessed the site.

IP Address Displays the IP address from which traffic was generated.

Category The requested URL’s categories as described in"Category descriptions "

on page 78. Displays Uncategorized if the URL has no category.

URL The URL address that the user has accessed.

Size Displays the file size in bytes. File sizes contribute to bandwidth usage.

Search Engine String The query string typed by the user to make searches on the web.

-169

-WSS 4.4.0-2

In document Admin Guide for Web Security Service (Page 173-178)