セキュリティとネットワークポリシーのルールヒット数レポートの生成

Prev Next

概要

Cato は、レポート期間中にトラフィックがポリシールールと一致した回数を示す定義済みレポートテンプレートを提供します。 これにより、削除可能な未使用のルールを特定し、必要なトラフィックスコープにより合ったルール設定を最適化することができます。 ルールのヒット数は、そのルールによって生成されたイベントの数に基づきます。 ルールがイベントを生成しないように設定されている場合、ヒット数はゼロになります。

これらのポリシー用にヒット数レポートを生成できます:

  • インターネットファイアウォール

  • WANファイアウォール

  • ネットワークルール

再発またはワンタイムレポート用のテンプレートを作成し、定義済みの時間範囲でレポートに含まれるサイトおよびSDPユーザーを含めます。 デフォルトでは、定義済みヒット数レポートテンプレートは、過去週の全てのサイトとSDPユーザーのトラフィックとデータを表示します。

レポートの操作については、Cato Reportsをご参照ください。

predefined_reports.png

定期的なヒット数レポートの作成

Create a new recurring report by defining the Filters for the items included in the report, as well as the Schedule which defines how often the report is generated - every two minutes, daily, weekly, or monthly. Generated reports are stored in the Cato Cloud, and they can be automatically emailed or downloaded. The Schedule also defines the time range that is covered by each report.

You can select a mailing list of email addresses for the recipients, which can include Cato Management Application admins, and external users.

For more information about Mailing Lists, see Working with Mailing Lists.

To create a recurring report:

  1. From the navigation pane, select Home > Reports.

  2. From the Catalog tab, find and select the template you want to use to generate the report.

  3. Click Generate > Create Schedule.

  4. Enter a Report Name.

  5. (Optional) In Filters, select specific sites or users for the predefined report.

    By default, the predefined report includes all sites and users.

  6. Define when the report will be generated and sent:

    1. Select the Frequency.

    2. For Weekly and Monthly scheduled reports, in Every select the day that the report is sent.

    3. Select the timezone.

  7. Select the export format: PDF or CSV.

  8. In Subscriptions, select the Mailing List that receives the report.

    You can click New to create a new mailing list.

  9. Click Save Schedule. The report is added to the Saved Reports tab.

Generating a Recurring Report On Demand

Recurring reports are automatically generated based on their schedule settings. For example, a weekly report configured for Monday, is generated every Monday. You can also choose to manually generate a recurring report on demand, in which case the generated report uses the defined time range based on the current day. If an admin manually generates a weekly report on a Tuesday, the time range for the report is the previous 7 days starting from that Tuesday, regardless of the starting day of the recurring report. For more information about the time range of recurring reports, see Cato Reports.

To generate a recurring report on demand:

  1. From the navigation pane, select Home > Reports.

  2. From the Saved Reports tab, find the recurring report and click Generate Now.

  3. From the Generated PDFs tab, find the report and click Download.

ワンタイムヒット数レポートの作成

ヒット数テンプレートに基づいてワンタイムレポートを作成できます。 レポートに含まれるアイテム用のフィルターを定義します。

To create a one-time report:

  1. From the navigation pane, select Home > Reports.

  2. From the Catalog tab, select the template you want to use to generate the report.

  3. Select Generate > Generate Now.

  4. Enter a Report Name.

  5. Define the relevant Filters for your report.
    These are specific to the report type.

  6. Define the Timeframe and Timezone of the report.

  7. Select the Format: PDF or CSV.

  8. Click Generate.
    The report is generated, and you can download it from the Generated tab.

ヒット数レポートの理解

ルールのヒット数は、そのルールによって生成されたイベントの数に基づいています。 ルールがイベントを生成しないように設定されている場合、ヒット数はゼロです。

ヒット数レポートには次のセクションがあります:

  • トップ/最小ルール

    • トップ一致ルール - ヒット数と共に上位20の一致するポリシールールのリスト

    • 最小一致ルール - ヒット数と共に最小の一致するポリシールールのリスト

  • ルールヒット数 - すべてのルールのリストを優先順位順に表示し、各ルールごとに生成されたイベント数、ルール名、および最も最近生成されたイベントのタイムスタンプを示します