<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebSpy Blog&#187; Scott &#8211; WebSpy Blog</title>
	<atom:link href="http://www.webspy.com.au/blogs/index.php/author/scott/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webspy.com.au/blogs</link>
	<description>For when WebSpyrians have something to say.</description>
	<lastBuildDate>Fri, 09 Dec 2011 01:18:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Running Multiple Instances of Vantage</title>
		<link>http://www.webspy.com.au/blogs/index.php/running-multiple-instances-of-vantage/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/running-multiple-instances-of-vantage/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 02:20:43 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[Locking]]></category>
		<category><![CDATA[Multiple Instance]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Storage]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2496</guid>
		<description><![CDATA[In the latest Vantage auto-update (2.2.0.68), we&#8217;ve included an experimental feature to allow multiple instances of WebSpy Vantage to run on the same operating system. The goal here is to run reports at the same time using multiple instances of the application. To do this, we have also include a second experimental feature to disable [...]]]></description>
			<content:encoded><![CDATA[<p>In the latest Vantage auto-update (2.2.0.68), we&#8217;ve included an experimental feature to allow multiple instances of WebSpy Vantage to run on the same operating system. The goal here is to run reports at the same time using multiple instances of the application. To do this, we have also include a second experimental feature to disable storage locking. This allows multiple instances of Vantage to read from the same storage at once.<span id="more-2496"></span></p>
<blockquote><p><strong>WARNING: With storage locking disabled, it is possible to import into a storage while running a report, and <span style="color: #ff0000;">doing this may cause storage corruption</span>. It is therefore very important if you decide to enable these features to ensure that a storage is not written to while running reports</strong>.</p></blockquote>
<p>Due to the experimental nature of these features, they can only be enabled by including a config file next to Vantage&#8217;s executable. To enable multi-instance capabilities and disable storage locking:</p>
<ol>
<li>Download the following config file:<br />
<a href="http://www.webspy.com.au/blogs/wp-content/uploads/2011/01/WebSpy.Vantage.exe.config.zip">WebSpy.Vantage.exe.config</a></li>
<li>Close Vantage</li>
<li>Extract downloaded zip file into Vantage&#8217;s installation folder (usually c:\Program Files (x86)\WebSpy\Vantage &lt;flavour&gt; 2.2). If you already have a file of the same name in that location, make a backup of it before overwriting it with the  new file.</li>
<li>Run Vantage.</li>
</ol>
<p>You can now run Vantage again to launch another instance of the application.</p>
<h2>Be aware of:</h2>
<h3>Simultaneous reading and writing, and multiple writes</h3>
<p>I just want to be very clear that if you run reports while importing, or import into the same storage simultaneously, storage corruption can occur. Storages are not designed to be unlocked for these reasons. The only reason we&#8217;ve provided this ability is so that you can READ from the a single storage  simultaneously (i.e. run two or more reports). Reading and writing, and multiple writing is NOT supported, but Vantage will attempt to do it if you ask it to, with undefined behavior.  Check your Tasks configuration and note when any import jobs are likely to occur to avoid running reports at these times.</p>
<h3>Configuration Changes</h3>
<p>When Vantage closes it writes all of it&#8217;s state to a series of files under c:\users\&lt;user profile&gt;\AppData\Roaming\WebSpy\Vantage &lt;flavour&gt; 2.2). When Vantage opens, it loads these files into memory. When  running multiple instances, these instances will be reading and writing the same files. So if you open two instances of Vantage, make a change to a report template in one instance, then close the application, the Vantage.Templates file will be updated. But when you close the second instance of the application, the Vantage.Templates file will be overwritten with a version that doesn&#8217;t include the change.</p>
<p>When making configuration changes (templates, tasks, aliases, organization etc), make sure only one instance is running (check Task Manager for the WebSpy.Vantage.exe process).</p>
<h3>It&#8217;s Experimental!</h3>
<p>There may be other undefined behaviors that we are yet unaware of, so we advise running this configuration in a test environment.</p>
<p>We&#8217;re providing these feature on an &#8220;as-is&#8221; basis, meaning we will not be providing technical support for issues that arise as a result. That said, we are certainly interested to hear about any issue to help us improve the feature.</p>
<p>Let us know how you go!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/running-multiple-instances-of-vantage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.68 (Exchange 2010, Juniper and IronPort Traffic Logs, and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 02:18:27 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[fixes]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Squid]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2494</guid>
		<description><![CDATA[We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.
Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as [...]]]></description>
			<content:encoded><![CDATA[<p>We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.</p>
<p>Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as JunOS (Juniper) Traffic Logs, IronPort Traffic Monitor Logs and Squid Syslog.<span id="more-2494"></span></p>
<p>We&#8217;ve also included an experimental feature to allow multiple instances of WebSpy Vantage to run on the same operating system. The goal here is to run multiple reports at the same time using multiple instances of the application. To do this, we have also included a second experimental feature to disable storage locking. This allows multiple instances of Vantage to read from the same storage at once. These features can only be enabled by including a config file next to the Vantage&#8217;s executable. <a title="Running Multiple=">More on this feature here</a>.</p>
<p>Here&#8217;s the full list of changes:</p>
<h3>Application Changes</h3>
<ul>
<li>New: Added suffix option to Import Windows Users wizard in Aliases.</li>
<li>New: Date modifiers now supports h for hour and n for minute, e.g. %[-2h,yyyyMM - HH].</li>
<li>New: Added tracing to storage publish task.</li>
<li>Experimental: Multiple instances of Vantage can now be run simultaneously, by adding the multipleInstance key to the application config file.</li>
<li>Experimental: Storage locking can be turned off to allow multiple instances of Vantage to run reports on a single storage simultaneously. This is done by adding the storageLocking key to the application config file.</li>
<li>Fix: Import Organization merge options now appends attributes if keep existing user details is selected, and replaces attributes if update user details from the directory is selected.</li>
<li>Fix: Import Organization merge no longer replaces user&#8217;s passwords.</li>
<li>Fix: Fixed issue where no results were returned when filtering on time less than one day – such as past n hours.</li>
<li>Fix: Storages are no longer duplicated in the Import new hits task dialog.</li>
<li>Fix: Fixed issues where the Site Domain summary included sub-domains for European domains (.fr, .be etc).</li>
<li>Fix: SQL server inputs now commit correctly if the user edits the input and only changes the port number.</li>
</ul>
<h3>Loader Changes</h3>
<ul>
<li>New: IronPort Traffic Monitor Logs.</li>
<li>New: Juniper JunOS Traffic Logs (SRX).</li>
<li>New: Microsoft Exchange 2010.</li>
<li>New: Squid Syslog.</li>
<li>Improved: Astaro Security Gateway: Added support for an additional different syslog header.</li>
<li>Improved: SonicWall: Split syslog format into Web and Firewall schemas, added support for User field, string-type Category field and split Protocol field.</li>
<li>Fix: Microsoft FTMG: Changed type of Object Source field in from Int32 to String. Users will need to clear/field select/reload their storages before this change will apply.</li>
<li>Fix: Astaro Mail Gateway: Improved format detection, fixed negative size issue, and Index out of bounds errors.</li>
<li>Fix: IronPort WSA: Improved format detection.</li>
</ul>
<p><strong>How to update</strong></p>
<p>To update your software, simply click <strong>Tools | Check for updates</strong>. Vantage Ultimate users will also need to update the Web Module in order to use the new loader formats that have been added. To update the Vantage Web Module, right-click the WebSpy system tray icon and select ‘Check for updates’. If you have issues with the Web Module update process, please see: <a title="Web Module Update Issues" href="http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29</a></p>
<p>Let me know if you have any questions or issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Creating and Analyzing SonicWALL Log Files</title>
		<link>http://www.webspy.com.au/blogs/index.php/creating-and-analyzing-sonicwall-log-files/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/creating-and-analyzing-sonicwall-log-files/#comments</comments>
		<pubDate>Wed, 22 Dec 2010 07:28:52 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[Categories]]></category>
		<category><![CDATA[drilldowns]]></category>
		<category><![CDATA[Internet Usage]]></category>
		<category><![CDATA[Kiwi]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Sites]]></category>
		<category><![CDATA[SonicWall]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[Web Reports]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2463</guid>
		<description><![CDATA[I&#8217;ve put together a couple of quick videos to show you how to configure logging on your SonicWALL appliance, and how to import and analyze these log files in WebSpy Vantage.
You can also read through these steps on this page:  Analyzing SonicWALL log files with WebSpy.

Creating and Importing SonicWALL log files

Analyzing SonicWALL log files

We [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve put together a couple of quick videos to show you how to configure logging on your SonicWALL appliance, and how to import and analyze these log files in WebSpy Vantage.</p>
<p>You can also read through these steps on this page:  <a title="Analyzing and Reporting on SonicWALL log files" href="http://www.webspy.com/vendors/sonicwall/howto.aspx" target="_blank">Analyzing SonicWALL log files with WebSpy</a>.</p>
<p><span id="more-2463"></span></p>
<h3>Creating and Importing SonicWALL log files</h3>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgo3vbQI" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="300" src="http://blip.tv/play/hLYlgo3vbQI" allowfullscreen="true"></embed></object></p>
<h3>Analyzing SonicWALL log files</h3>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgpa_OgA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="300" src="http://blip.tv/play/hLYlgpa_OgA" allowfullscreen="true"></embed></object></p>
<p>We intend to make some SonicWALL specific report templates available on our <a title="How to Report on SonicWALL Log Files" href="http://www.webspy.com.au/vendors/sonicwall/" target="_blank">SonicWALL how to</a> page soon.</p>
<p>Until then, feel free to create your own templates, or modify our existing web reports to include the extra goodies contained in the SonicWALL logs.</p>
<p>TIP: To modify an existing web report, right-click the report and choose ‘Duplicate template’. Then choose the “SonicWall Web” schema. You’ll then have a report template that you can modify to include all the SonicWALL summaries, such as Categories, and Source and Destination Interface.</p>
<p>If you need some assistance getting the report(s) you need, feel free to contact me, or support@webspy.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/creating-and-analyzing-sonicwall-log-files/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Reporting on Astaro Security Gateway</title>
		<link>http://www.webspy.com.au/blogs/index.php/reporting-on-astaro-security-gateway/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/reporting-on-astaro-security-gateway/#comments</comments>
		<pubDate>Fri, 10 Dec 2010 07:23:54 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Astaro]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Log Files]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Security Gateway]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2450</guid>
		<description><![CDATA[Astaro Security Gateway devices are capable of producing some very detailed log files including full URLs, usernames, categories, block action and reason which gives you some great reporting options in WebSpy Vantage.
Take a look at our dedicated Astaro pages to get an idea of what can be achieved when analyzing Astaro Web Gateway log files [...]]]></description>
			<content:encoded><![CDATA[<p>Astaro Security Gateway devices are capable of producing some very detailed log files including full URLs, usernames, categories, block action and reason which gives you some great reporting options in WebSpy Vantage.</p>
<p>Take a look at our dedicated Astaro pages to get an idea of what can be achieved when <a title="Reporting on Astaro Security Gateway Log Files with WebSpy Vantage" href="http://www.webspy.com/vendors/astaro" target="_blank">analyzing Astaro Web Gateway log files with WebSpy Vantage</a>.</p>
<p>I&#8217;ve created some quick videos to show you how to enable the correct logging options on the Astaro Security Gateway appliance, how to import these log files into Vantage, and analyze the data on the Summaries screen.<span id="more-2450"></span></p>
<h3>Configure Logging</h3>
<p>The best way to configure logging is to setup a 3rd party syslog server (such as Kiwi Syslog) on a machine in your network, then configure the Astaro Security Gateway to send syslog messages to that server. The syslog server then creates log files that can be imported into WebSpy Vantage. This video takes you through that process.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgo%2BTagI" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="300" src="http://blip.tv/play/hLYlgo%2BTagI" allowfullscreen="true"></embed></object></p>
<h3>Importing and Analyzing Astaro logs</h3>
<p>Once you have successfully configured syslogging on your Astaro Security Gateway, you can import the log files into WebSpy Vantage and analyze activity on the Summaries screen. This video takes you through that process.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgo%2BUAwI" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="300" src="http://blip.tv/play/hLYlgo%2BUAwI" allowfullscreen="true"></embed></object></p>
<p>We intend to make some Astaro specific report templates available on our <a title="How to Analyze your Astaro Log files in WebSpy Vantage" href="http://www.webspy.com/vendors/astaro/howto.aspx" target="_blank">Astaro How To</a> page soon.</p>
<p>Until then, feel free to create your own templates, or modify our existing web reports to include the extra goodies contained in the Astaro logs.</p>
<p><em>TIP: To modify an existing web report, right-click the report and choose &#8216;Duplicate template&#8217;. Then choose the &#8220;Astaro Security Gateway &#8211; Filter with category&#8221; schema. You&#8217;ll then have a report template that you can modify to include all the Astaro summaries, such as Actions and Categories.</em></p>
<p>If you need some assistance getting the report(s) you need, feel free to contact me, or support@webspy.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/reporting-on-astaro-security-gateway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How much do IronPort WSA Appliances eat?</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-much-do-ironport-wsa-appliances-eat/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-much-do-ironport-wsa-appliances-eat/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 05:32:47 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[Access Logs]]></category>
		<category><![CDATA[Cisco IronPort]]></category>
		<category><![CDATA[Disk]]></category>
		<category><![CDATA[HDD]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[Requirements]]></category>
		<category><![CDATA[Size]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Web Security Appliances]]></category>
		<category><![CDATA[WebSpy Storage]]></category>
		<category><![CDATA[WSA]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2384</guid>
		<description><![CDATA[If you are thinking about deploying IronPort Web Security Appliances you probably want to plan how much disk space to budget for with regards to logging and reporting.
Every organization is different with regards to the volume of logs it creates, but I&#8217;ve averaged three data sets submitted to us by customers to produce the following [...]]]></description>
			<content:encoded><![CDATA[<p>If you are thinking about deploying IronPort Web Security Appliances you probably want to plan how much disk space to budget for with regards to logging and reporting.</p>
<p>Every organization is different with regards to the volume of logs it creates, but I&#8217;ve averaged three data sets submitted to us by customers to produce the following estimates.<span id="more-2384"></span></p>
<p>You will create roughly <strong>0.9 MB</strong> of IronPort WSA access logs per user per day.</p>
<p>Once imported into a WebSpy Storage, the Storage will be about<strong> 90%</strong> of your original log file size. If you apply NTFS compression to the storage folder, the actual size on disk of the WebSpy Storage will be about <strong>30%</strong> of your original log data.</p>
<p>So an organization with <strong>1000 user</strong>s will produce about <strong>900 MBs</strong> of access logs per day. The default WebSpy Storage  will be <strong>810 MB,</strong> but with NTFS compression, the size on disk will around <strong>270 MB</strong>.</p>
<p>As I said, this is a rough guide based on the average of three sets of sample logs we have in house, so please run your own tests and if you can, let us know your values in the comments below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-much-do-ironport-wsa-appliances-eat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Watch your TMG&#8217;s waist line. Switch log format and reduce fat now!</title>
		<link>http://www.webspy.com.au/blogs/index.php/watch-your-tmgs-waist-line-switch-log-format-and-reduce-fat-now/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/watch-your-tmgs-waist-line-switch-log-format-and-reduce-fat-now/#comments</comments>
		<pubDate>Wed, 27 Oct 2010 04:57:46 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[disk space]]></category>
		<category><![CDATA[Disk Usage]]></category>
		<category><![CDATA[Forefront TMG]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MSDE]]></category>
		<category><![CDATA[SQL Express]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Text Logging]]></category>
		<category><![CDATA[Threat Management Gateway]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[W3C]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2251</guid>
		<description><![CDATA[We often recommend customers using Microsoft ISA or TMG switch their logging to W3C text file, in order to get the best possible import speed, and also because the text logs are much easier to access from a remote machine (see my previous article on accessing TMG&#8217;s SQL Express Log database). Logging to the default [...]]]></description>
			<content:encoded><![CDATA[<p>We often recommend customers using Microsoft ISA or TMG switch their logging to W3C text file, in order to get the best possible import speed, and also because the text logs are much easier to access from a remote machine (see my previous article on <a title="Accessing Microsoft TMG's SQL Express Log File Database" href="http://www.webspy.com.au/blogs/index.php/accessing-microsoft-forefront-tmgs-log-files-sql-express/" target="_blank">accessing TMG&#8217;s SQL Express Log database</a>). Logging to the default MSDE or SQL Express databases also requires more resources in terms of processor utilization, memory consumption and disk I/O.</p>
<p>But there is another advantage to switching to text. They take up considerably less disk space. Here are some figures:</p>
<p><span id="more-2251"></span></p>
<h2>Number of Records in 235 MBs of log data:</h2>
<p><img class="size-full wp-image-2256" title="Number of Records in 235MB of TMG logs" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/10/Number-of-Records-in-235MB-of-logs1.png" alt="Number of Records in 235MB of TMG logs" width="369" height="250" /><br />
235 MB of TMG&#8217;s W3C text logs contains 326,824 records. An SQL Express database of the same size (mdf and ldf files) contains only 40,308 records. In other words, w3C text logs can store over 8 times as much data in the same amount of disk space.</p>
<h2>A rule of thumb:</h2>
<p>By switching to W3C text logs, the disk space taken by your log files will be roughly 12% of the SQL Express or MSDE log files. This can be reduced even further by compressing your text logs.</p>
<ul>
<li>MSDE/SQL logs: budget for <strong>5 KB per record</strong></li>
<li>W3C Text logs: budget for <strong>0.71 KB per record</strong></li>
</ul>
<p>How many records your ISA or TMG server creates per day will depend on the number of users in your organization and how much traffic they generate, but about 16,000 records per user is a reasonable estimate.</p>
<h2>A real world example</h2>
<p>If you are hitting<strong> 500 GB</strong> of SQL Express/ MSDE logs per month (about 86,128,205 records), simply switching to W3C text logs will reduce this down to <strong>61 GB</strong>.<br />
<img class="size-full wp-image-2259" title="Log File Size - SQL Express vs W3C Text files (86,128,205 records)" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/10/Log-Size.png" alt="Log File Size - SQL Express vs W3C Text files (86,128,205 records)" width="421" height="241" /></p>
<p>Once imported into a WebSpy Storage, the storage size would be roughly <strong>53 GB (</strong>87% of the original W3C text logs).</p>
<p>With NTFS compression applied to the Storage folder, the WebSpy Storage would be roughly <strong>13.4 GB (</strong>22% of the original W3C text logs).</p>
<p>Applying NTFS compression to your WebSpy Storages folder is certainly a good idea. This does not impact performance. If anything, it may improve performance slightly as there is less disk fragmentation within the storage.</p>
<h2>Disadvantages and Alternatives</h2>
<p>Please be aware that by changing your logging to text, the default reporting functionality within TMG will no longer work. However, the reporting supplied by WebSpy Vantage should <a title="8 Reasons Not to use Microsoft Forefront TMG's default reporting" href="http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/" target="_blank">more than adequately replace this feature</a>.</p>
<p>If you are still concerned about changing the logging method, you can utilize a script published by Microsoft to convert your SQL Express logs to W3C text.  You can then keep the text logs and set some more stringent data retention policies on the SQL Express logs, such as clearing logs every week. You can download this script as part of the <a title="Microsoft TMG 2010 Tools and Software Development Kit (SDK)" href="http://www.microsoft.com/downloads/en/details.aspx?familyid=8809CFDA-2EE1-4E67-B993-6F9A20E08607&amp;displaylang=en" target="_blank">Microsoft Forefront Threat Management Gateway (TMG) 2010 Tools &amp; Software Development Kit</a>.</p>
<h2>Additional Resources</h2>
<ul>
<li>Here&#8217;s a great article by Marc Grote at <a href="http://isaserver.org">isaserver.org</a> on the pros and cons of the different logging options in ISA and TMG. It also takes you through how to exclude fields to reduce the amount of data being logged:<br />
<a title="Microsoft Forefront TMG Logging Options" href="http://www.isaserver.org/tutorials/Microsoft-Forefront-TMG-Logging-options-Forefront-TMG.html" target="_blank">http://www.isaserver.org/tutorials/Microsoft-Forefront-TMG-Logging-options-Forefront-TMG.html</a></li>
<li>Also take a look at Richard Hicks&#8217; blog regarding MSDE performance with ISA Server 2006:<br />
<a title="MSDE Performance with Microsoft ISA Server 2006" href="http://tmgblog.richardhicks.com/2009/10/31/msde-performance-with-microsoft-isa-server-2006/" target="_blank">http://tmgblog.richardhicks.com/2009/10/31/msde-performance-with-microsoft-isa-server-2006/</a></li>
<li>Here&#8217;s another article on <a href="http://isaserver.org/">isaserver.org</a> by Richard Hicks on the logging enhancements in TMG 2010<br />
<a href="http://www.isaserver.org/articles/Logging-Enhancement-Microsoft-Forefront-Threat-Management-Gateway-TMG-2010.html&quot;" target="_blank">http://www.isaserver.org/articles/Logging-Enhancement-Microsoft-Forefront-Threat-Management-Gateway-TMG-2010.html</a></li>
</ul>
<p>The figures above were produced using some sample logs received from customers with similar (but not exactly the same) logging settings. If you have changed to text logging, I&#8217;d be very interested to hear the sort of disk savings you are seeing, and I&#8217;m sure others would to. So please leave a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/watch-your-tmgs-waist-line-switch-log-format-and-reduce-fat-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.55 (Clearswift, Palo Alto Networks, WatchGuard and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 07:25:56 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[ClearSwift]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[FlowMonitor]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Partners]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[IOS Firewall]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Microsoft ISA]]></category>
		<category><![CDATA[PA Firewall]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[SECURE Web Gateway]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[Watchguard]]></category>
		<category><![CDATA[Web Security Appliance]]></category>
		<category><![CDATA[XTM]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2196</guid>
		<description><![CDATA[We&#8217;ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats.
What&#8217;s New?
Clearswift SECURE Web Gateway W3C
Clearswift have just released the latest version of their SECURE Web Gateway, which includes a transaction log export function. This enables you to send transaction logs [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats.<span id="more-2196"></span></p>
<h2>What&#8217;s New?</h2>
<h3>Clearswift SECURE Web Gateway W3C</h3>
<p>Clearswift have just released the latest version of their SECURE Web Gateway, which includes a transaction log export function. This enables you to send transaction logs in W3C format to an off-box FTP server for analysis. If you are updating to the latest Clearswift SECURE Web Gateway, make sure you update your Vantage software to 2.2.0.55 in order to import your W3C Transaction logs. <a title="Using WebSpy Vantage with ClearSwift SECURE Web Gateway" href="http://www.webspy.com/vendors/clearswift/howto.aspx" target="_blank">More information on using WebSpy Vantage with Clearswift SECURE Web Gateway</a>.</p>
<h3>Cisco Firewall Bandwidth loader</h3>
<p>We have also introduced a new Loader for Cisco ASA, PIX and IOS Firewall devices. This new loader imports TCP, UDP, ICMP and GRE &#8217;session close&#8217; events into one schema, allowing you to aggregate size values across these  events. This loader is called Cisco Firewall (Bandwidth) and is now available on the Loader Selection page of the Import Wizard. Previously, these events were imported into separate schemas so there was no great way to determine total bandwidth from your Cisco syslog files (<a title="How to report on bandwidth utilization using Netflow and WebSpy FlowMonitor" href="http://www.webspy.com.au/blogs/index.php/how-to-report-on-bandwidth-utilization-using-cisco-devices/" target="_blank">without using Netflow and WebSpy FlowMonitor</a>).</p>
<h3>Palo Alto Networks and WatchGuard XTM</h3>
<p>We&#8217;re also very happy to welcome Palo Alto Networks to the WebSpy supported log file list. Vantage now supports both the CSV and syslog file formats from your PA Firewall.</p>
<p>Another new addition is support for the latest WatchGuard XTM devices running firmware version 11.</p>
<h2>Full List of Changes</h2>
<p>Here&#8217;s the full list of changes included in this update:</p>
<ul>
<li>New: Clearswift SECURE Web Gateway W3C.</li>
<li>New: Palo Alto Networks Firewall (CSV/Syslog)</li>
<li>New: Cisco Firewall (Bandwidth): This new Cisco loader imports TCP, UDP, ICMP and GRE events from ASA, PIX and IOS syslogs into one schema to aggregate size values across these events.</li>
<li>New: Added WatchGuard XTM: Currently http-proxy, https-proxy, smtp-proxy and firewall lines are supported.</li>
<li>Fixed: ISA Server: Fixed format detection issues, and issues importing hits with very large size values.</li>
<li>Fixed: IronPort WSA: Fixed format detection issues, as well as the import issue &#8220;Invalid value for DVS Scan Code&#8221;</li>
<li>Fixed: Sophos WSA: Fixed format detection issues and invalid line issues.</li>
</ul>
<h2>How to update</h2>
<p>To update your software, simply click <strong>Tools | Check for updates</strong>. To update the Vantage Web Module, right-click the WebSpy system tray icon and select &#8216;Check for updates&#8217;. If you have issues with the Web Module update process, please see: <a title="Web Module Update Issues" href="http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29</a></p>
<p>Let me know if you have any questions or issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful LDAP Search Queries</title>
		<link>http://www.webspy.com.au/blogs/index.php/useful-ldap-search-queries/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/useful-ldap-search-queries/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 04:35:12 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Aliases]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Computers]]></category>
		<category><![CDATA[Disabled Users]]></category>
		<category><![CDATA[Filters]]></category>
		<category><![CDATA[Import Organization]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[Query]]></category>
		<category><![CDATA[Users]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2177</guid>
		<description><![CDATA[Today I was asked how to filter out computer objects when importing your Organizational structure into WebSpy Vantage.
The default LDAP query when you first run through the Import Organization wizard should filter these computers objects out. The query is:
(&#38;(objectCategory=person)(objectClass=user))
In Active Directory, computers do not generally have an objectCategory equal to Person. Computers usually have the [...]]]></description>
			<content:encoded><![CDATA[<p>Today I was asked how to filter out computer objects when importing your Organizational structure into WebSpy Vantage.</p>
<p>The default LDAP query when you first run through the Import Organization wizard should filter these computers objects out. The query is:<span id="more-2177"></span><br />
<code>(&amp;(objectCategory=person)(objectClass=user))</code></p>
<p>In Active Directory, computers do not generally have an objectCategory equal to Person. Computers usually have the objectCategory &#8216;Computer&#8217;.</p>
<p>If by chance your computers are not being excluded by this filter, you could exclude all objects without an email address. This of course assumes that all users you want to import have an email address populated in Active Directory. To exclude objects without email addresses, the filter becomes:</p>
<p><code>(&amp;(objectCategory=person)<strong>(mail=*)</strong>(objectClass=user))</code></p>
<p>Another useful addition to the query is to exclude users that have been disabled in Active Directory. You usually disable an account when a person leaves the organization, but you still need their user profile in Active Directory for whatever reason. This query is slightly less obvious:<br />
<code><br />
(&amp;(objectCategory=person)(mail=*)(objectClass=user)<strong>(!(userAccountControl:1.2.840.113556.1.4.803:=2))</strong>)</code></p>
<p>For information on what the numbers mean in the query above, see <a title="How to query Active Directory using a bitwise Filter" href="http://support.microsoft.com/kb/269181" target="_blank">How to query Active Directory using a bitwise Filter</a></p>
<p>Another question I&#8217;m often asked is how to exclude specific OUs from a query. Unfortunately LDAP does not support this concept and the only way to do this is to run multiple queries on different root level DNs. This means running through the Import Organization wizard multiple times with a different Root Distinguished Name each time, and the &#8216;Merge&#8217; options set to &#8216;Keep users that are no longer in the directory&#8217; and &#8216;Keep existing user details&#8217;.</p>
<p>If you have other helpful LDAP queries, please leave a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/useful-ldap-search-queries/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.51 (UrlCategory Fix for Microsoft TMG)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-51-urlcategory-fix/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-51-urlcategory-fix/#comments</comments>
		<pubDate>Thu, 26 Aug 2010 08:34:48 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[fix]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[Log Files]]></category>
		<category><![CDATA[microsoft Forefront TMG]]></category>
		<category><![CDATA[Software update]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[Url Category]]></category>
		<category><![CDATA[UrlCategory]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2094</guid>
		<description><![CDATA[We have released an update to the Vantage range of applications to fix an issue with the Microsoft Forefront Threat Management Gateway (TMG) loader. 
An issue was introduced in build 2.2.0.42 when a change was made to the underlying data type of the Url Category field in the Microsoft TMG Web Schema. Unfortunately this change [...]]]></description>
			<content:encoded><![CDATA[<p>We have released an update to the Vantage range of applications to fix an issue with the Microsoft Forefront Threat Management Gateway (TMG) loader. <span id="more-2094"></span></p>
<p>An issue was introduced in build 2.2.0.42 when a change was made to the underlying data type of the Url Category field in the Microsoft TMG Web Schema. Unfortunately this change resulted in nulls being imported into the Url Category summary when importing from TMG&#8217;s SQL log files. Fortunately, importing W3C text logs were unaffected by this change.</p>
<p>This issue has now been fixed and released as an auto-update. To update your software simply select <strong>Tools | Check for updates</strong>.</p>
<p>If you have existing storages that have not been importing the URL Category, go to the storages screen and click &#8216;Reload All&#8217;. This will re-import your log files and populate the Url Category summary.</p>
<p>For all the customers affected by this issue, thank you for your patience and understanding.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-51-urlcategory-fix/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.50 (Juniper SA, Forefront Protection and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-50/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-50/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 05:43:03 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Avencis]]></category>
		<category><![CDATA[Forefront Protection for Exchange]]></category>
		<category><![CDATA[IAS Radius]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Loader]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2070</guid>
		<description><![CDATA[We have just released an auto update for the Vantage range of applications. This update includes support for the Juniper SA series and Microsoft Forefront Protection for Exchange 2010.
Here&#8217;s the full list of changes:

 New: Juniper SA Series. Vantage can import and report on web traffic and VPN connections.
 New: Microsoft Forefront Protection for Exchange [...]]]></description>
			<content:encoded><![CDATA[<p>We have just released an auto update for the Vantage range of applications. This update includes support for the Juniper SA series and Microsoft Forefront Protection for Exchange 2010.</p>
<p>Here&#8217;s the full list of changes:</p>
<ul>
<li> New: Juniper SA Series. Vantage can import and report on web traffic and VPN connections.</li>
<li> New: Microsoft Forefront Protection for Exchange 2010 format.</li>
<li> New: Avencis SSOx.</li>
<li> Improved: IronPort WSA: Department and Message fields were sometimes returned as null. Fixed.</li>
<li> Improved: Microsoft FTMG: Removed usage of deprecated &#8220;FilterInfo&#8221; field from W3C Web format.</li>
<li> Improved: Microsoft IAS Radius: Added support for Source/Destination IP and port (field code 5000).</li>
</ul>
<p><span id="more-2070"></span>To update your Vantage application simply select <strong>Tools | Check for updates</strong>. </p>
<p>To update the Vantage Web Module, right-click the WebSpy icon in the Web Module server&#8217;s system tray, and select <strong>Check for updates</strong>. If you have any issues with the Web Module update process, please see my previous blog regarding <a title="Web Module Errors and Workarounds" href="http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/" target="_blank">Web Module Errors and Workarounds</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-50/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.48 &#8211; New Loaders, Features and Fixes</title>
		<link>http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 06:43:53 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[errors]]></category>
		<category><![CDATA[fixes]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2003</guid>
		<description><![CDATA[We&#8217;ve just released an update to the Vantage range of application, including the Web Module.
This release will be welcomed with open arms by many customers for the following reasons:

General usability improvements in the Web Module
Multi-select / delete options, Ajax progress indicators to avoid page refreshes, export from Dynamics Report tab and more (see below)
Fixes to [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an update to the Vantage range of application, including the Web Module.</p>
<p>This release will be welcomed with open arms by many customers for the following reasons:</p>
<ul>
<li><strong>General usability improvements in the Web Module</strong><br />
Multi-select / delete options, Ajax progress indicators to avoid page refreshes, export from Dynamics Report tab and more (see below)</li>
<li><strong>Fixes to the Microsoft Forefront TMG loader </strong><br />
See my other post: <a title="Microsoft Forefront TMG logs size fields the wrong way around" href="http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around" target="_blank">Microsoft Forefront TMG logs size fields the wrong way around</a>. Also fixed &#8216;value cannot be null&#8217; error when importing SQL logs.</li>
<li><strong>Fixes to storage corruption issues</strong><br />
This build should prevent &#8216;Normalization Index&#8217; storage corruption issues from occurring. This often occurred after importing data, editing some log inputs and reimporting.</li>
<li><strong>New loaders and more fixes</strong><br />
See below for the full list</li>
</ul>
<p><span id="more-2003"></span><br />
To update your Vantage application, simply choose <strong>Tools | Check for updates</strong>. To update the Web Module, right-click the WebSpy icon in your system tray and select &#8216;Check for updates&#8217;. If you have any issues updating the Web Module, please see my previous post <a title="Web Module Update Errors and Workarounds" href="http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/" target="_blank">Web Module Update Errors and Workarounds</a>.</p>
<p><strong>Web Module Changes:</strong></p>
<ul>
<li>New: Task progress is now updated without refreshing the page</li>
<li>New: Added multi-select / delete functionality to Reports, Analyses and Storages tables.</li>
<li>New: Added export functionality to Dynamic Reports view.</li>
<li>New: Added Performance section on the Options tab to enabling multi-processing (improves Analysis speed)</li>
<li>Fix: Dynamic Reports view now supports Trend reports.</li>
<li>Fix: Organization selector on Dynamic Reports view now always reflects updated data under IE6/7/8.Fix: Fixed javascript errors in IE when expanding the organization filter.</li>
<li>Fix: Report template names are no longer truncated on the Dynamic Reports view.</li>
<li>Fix: Fixed errors that may occur when collating reports on the Dynamic Reports page.</li>
<li>Fix: Authentication errors are now logged with stack trace.</li>
</ul>
<p><strong>Vantage Changes</strong></p>
<ul>
<li>Fixed: &#8216;Normalization index&#8217; storage corruption problems.</li>
<li>Fix: Report collation: Added support for collation of Min/Max aggregates on DateTime columns (time of first hit etc). Also added support for arrayed fields (for example, category fields with a comma separated list of categories)</li>
<li>Fix: Import windows wizard now remembers settings for Import all or selected users</li>
<li>Fix: Organization: Filtered LDIFs may now be imported when references to some users are missing (for example, if a user’s manager does not exist in the LDIF)</li>
<li>Fix: Improved connection and error handling between Vantage and the Web Module.</li>
</ul>
<p><strong> Loader Changes</strong></p>
<ul>
<li> New: BlueReef Sonar Total Management Module</li>
<li>New: Microsoft Sharepoint 2007</li>
<li>New: SmoothWall Guardian 7.0 format</li>
<li>New: Sun One Proxy (Supported under Sun One Webserver)</li>
<li>Fixed: Astaro: Improved format detection</li>
<li>Fixed: Cisco: Strings in the IP fields of 113019 lines are now imported</li>
<li>Fixed: IronPort WSA: Improved log format detection</li>
<li>Fixed: Microsoft Exchange 2007: No longer raises issues regarding total-bytes or internal-message-id fields</li>
<li>Fixed: Micorosft FTMG (Web) SQL: No longer encounters value could not be null errors</li>
<li>Fixed: Microsoft FTMG: Added option to reverse bytes received/sent fields. See <a href="http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around" target="_blank">Microsoft Forefront TMG logs size fields the wrong way around</a></li>
<li>Fixed: Microsoft IIS W3C: Now imports cs-method and connection ID</li>
<li>Fixed: Sophos Web Appliance: Switched the outgoing and ingoing sizes so that they are now the correct way around</li>
<li>Fixed: Fixed import new hits issue associated with W3C formats. You must reload your logs before this change will take affect. Formats affected include: BlueCoat, Clearswift, Microsoft Exchange 2007, Microsoft FTMG, Microsoft Windows Media Services, WebSpy Live Tracking Log</li>
</ul>
<p>Enjoy!</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 801px; width: 1px; height: 1px; overflow: hidden;">
<h2>Microsoft Forefront TMG logs size fields the wrong way around</h2>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Forefront TMG logs size fields the wrong way around</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 04:49:04 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[bytes received]]></category>
		<category><![CDATA[bytes sent]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[incorrect size]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2011</guid>
		<description><![CDATA[If you&#8217;re using Microsoft Forefront Threat Management Gateway, there is a bug in the logging that causes Bytes Sent and Bytes Received to be logged in reverse. This seems to only affect the Web Proxy logs &#8211; both SQL and W3c . We noticed in a few web reports, that people were generally uploading a [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re using Microsoft Forefront Threat Management Gateway, there is a bug in the logging that causes Bytes Sent and Bytes Received to be logged in reverse. This seems to only affect the Web Proxy logs &#8211; both SQL and W3c . We noticed in a few web reports, that people were generally uploading a lot more than they were downloading. So we checked the logs and verified the buggy behavior:<span id="more-2011"></span></p>
<div id="attachment_2012" class="wp-caption alignleft" style="width: 610px"><img class="size-full wp-image-2012" title="Microsoft TMG Log showing Bytes Sent consistently larger than Bytes Received" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/TMG-Bytes-Sent-Greater-than-Bytes-Receieved-e1280372795595.png" alt="Microsoft TMG Log showing Bytes Sent consistently larger than Bytes Received" width="600" height="261" /><p class="wp-caption-text">Microsoft TMG Log showing Bytes Sent consistently larger than Bytes Received</p></div>
<p><strong>This issue has been confirmed by the Microsoft Forefront TMG team, and unfortunately there is no ETA for a fix.</strong></p>
<p>We obviously don&#8217;t want our reports showing incorrect usage figures, so we&#8217;ve fixed our TMG loader so that it imports the &#8216;bytesrecvd&#8217; field into the Bytes Sent aggregate, and the &#8216;bytessent&#8217; field into the Byte Received aggregate.</p>
<p>But what if Microsoft release a fix? What we&#8217;ve done is implemented a loader property to allow you to turn off this behavior. This will allow you to import your old logs with the fields reversed, and your new logs with the fields the right way around.</p>
<p>To access the loader property:</p>
<ul>
<li> On the import wizard, select the Microsoft FTMG format and click the <strong>Properties </strong>button on the toolbar</li>
<li> Select Microsoft FTMG from the drop down list</li>
<li> Notice the option to &#8216;Reverse Bytes Sent and Received to compensate for bug in TMG&#8217;s logging&#8217;. Leave this checked until Microsoft issue a fix.</li>
</ul>
<div id="attachment_2024" class="wp-caption alignleft" style="width: 610px"><img class="size-full wp-image-2024" title="Microsoft TMG Option to Reverse Bytes Sent and Received" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/TMGReverseSentReceivedOption-e1280378741711.png" alt="Microsoft TMG Option to Reverse Bytes Sent and Received" width="600" height="386" /><p class="wp-caption-text">Microsoft Forefront TMG Loader Option to Reverse Bytes Sent and Received</p></div>
<p>This fix is available in <a title="Vantage Update 2.2.0.48 – New Loaders, Features and Fixes " href="http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/" target="_blank">Vantage build 2.2.0.48</a> (and above) which has been released as an auto update. So simply select<strong> Tools | Check for updates</strong> to ensure you have this fix.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why there is so much anonymous traffic in Microsoft TMG and ISA logs</title>
		<link>http://www.webspy.com.au/blogs/index.php/why-there-is-so-much-anonymous-traffic-in-microsoft-tmg-and-isa-logs/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/why-there-is-so-much-anonymous-traffic-in-microsoft-tmg-and-isa-logs/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 03:18:29 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Filter]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Proxy Authentication Required]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[requires authorization]]></category>
		<category><![CDATA[Result Code]]></category>
		<category><![CDATA[templates]]></category>
		<category><![CDATA[Threat Management Gateway]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[Unauthenticated]]></category>
		<category><![CDATA[user agent]]></category>
		<category><![CDATA[username]]></category>
		<category><![CDATA[windows update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1928</guid>
		<description><![CDATA[
One of the most common questions we get asked by users of Microsoft TMG and ISA is why there is so much traffic attributed to the Anonymous user. Even though unauthenticated access to the web has been disabled, they still see the &#8216;Anonymous&#8217; user as one of the top users in their reports.
So let&#8217;s use [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/Anonymous.png"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/Anonymous-300x164.png" alt="" title="Large percentage of anonymous traffic" width="300" height="164" class="size-medium wp-image-1933" style="float:right" /></a><br />
One of the most common questions we get asked by users of Microsoft TMG and ISA is why there is so much traffic attributed to the Anonymous user. Even though unauthenticated access to the web has been disabled, they still see the &#8216;Anonymous&#8217; user as one of the top users in their reports.</p>
<p>So let&#8217;s use WebSpy Vantage to drill into that Anonymous user and find out what is going on.<span id="more-1928"></span></p>
<p>One way to do this is to run an Ad-hoc analysis on the Summaries screen and drilldown into the Anonymous user to view all the information about that user. However, TMG and ISA tend to log a lot of information that may not be relevant to this particular investigation, so I&#8217;ve created some report templates (one for ISA and one for TMG) and a set of Aliases that pull out some relevant information.</p>
<h3>Download our Anonymous Traffic Investigation Report</h3>
<p>If you&#8217;re running WebSpy Vantage download the <a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/AnonymousTrafficReports.zip">Anonymous Traffic Report Templates &amp; Aliases</a></p>
<p>Then open the .Templates file on the Reports tab, and the .Aliases file on the Aliases tab. Once you have both files opened, go to the Reports tab and click either the &#8216;Anonymous Traffic Investigation (ISA)&#8217; or the &#8216;Anonymous Traffic Investigation (TMG)&#8217; report. Then click the &#8216;Generate report&#8217; link and run the report template on your ISA or TMG storage.</p>
<p>The report gives you the ability to drill into the Allowed, Denied and Failed traffic to see a list of the unauthenticated IPs, Sites, Rules responsible for blocking or allowing the traffic, unauthenticated Applications and Result Codes.</p>
<h3>Main causes of anonymous traffic</h3>
<p>What you will probably find is that most of the Anonymous traffic is being denied by your TMG or ISA firewall. When a client first requests a web page, the proxy will challenge the client for authentication. These events are often logged with the result code 12209 meaning &#8216;<em>authorization is required to fulfill the reques</em>t&#8217;. These requests are therefore denied by the proxy until the client&#8217;s credentials are authenticated.</p>
<p>Have a look at the amount of traffic being denied and then checkout the Result Codes associated with the denied traffic. Chances are you&#8217;ll see &#8216;proxy authentication required&#8217; appear predominantly.</p>
<p>If you also look at the Applications section you may also find that Windows Updates are sailing through   your TMG or ISA firewall unauthenticated.</p>
<h3>Filter out unauthenticated traffic from Reports</h3>
<p>The most logical next step is to filter out the information you do not want in your reports. You&#8217;ll probably still want to include Windows Update traffic in your reports, but you&#8217;re probably not so interested in the &#8216;proxy authentication required&#8217; information. So let&#8217;s filter that out.</p>
<p>To do this:</p>
<ol>
<li>Go to the Reports tab and select the report you want to filter (such as your Organization report)</li>
<li>Click &#8216;Edit Template&#8217;, then click &#8216;Template Properties&#8217;.</li>
<li>In the filter section at the bottom of the dialog, click <strong>Add | Field value filter</strong>.</li>
<li>Select the &#8216;Result Code&#8217; summary and select the Status Code Names (ISA-FTMG) alias.</li>
<li>On the toolbar, search for Authorization, and check the following two items:
<ul>
<li>The server requires authorization to fulfill the request. Access to the Web Proxy filter is denied.</li>
<li>The server requires authorization to fulfill the request. Access to the Web server is denied. Contact the server administrator.</li>
</ul>
</li>
<li>Ensure the &#8216;Exclude&#8217; radio button is selected and click <strong>OK</strong>.</li>
</ol>
<p>If you decide that you don&#8217;t care about seeing ANY unauthenticated traffic in your reports, you can always simply filter out the Anonymous user from your reports.</p>
<p>To do this:</p>
<ol>
<li>Go to the Reports tab and select the report you want to filter (such as your Organization report)</li>
<li>Click &#8216;Edit Template&#8217;, then click &#8216;Template Properties&#8217;.</li>
<li>In the filter section at the bottom of the dialog, click <strong>Add | Field value filter</strong>.</li>
<li>Select the &#8216;Username&#8217; summary.</li>
<li>On the toolbar, click <strong>Add </strong>and type &#8216;anonymous&#8217;. Click <strong>OK</strong>.</li>
<li>Ensure the Exclude radio button is selected and click <strong>OK</strong>.</li>
</ol>
<p>Hopefully this article improves your understanding of the &#8216;anonymous&#8217; user, and gives you some actions to take for your specific reporting situation.</p>
<p>If you have any questions, please leave a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/why-there-is-so-much-anonymous-traffic-in-microsoft-tmg-and-isa-logs/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Video: How to use WebSpy Vantage to report on IronPort log files</title>
		<link>http://www.webspy.com.au/blogs/index.php/video-how-to-use-webspy-vantage-to-report-on-ironport-log-files/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/video-how-to-use-webspy-vantage-to-report-on-ironport-log-files/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 02:01:16 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[dynamic reports]]></category>
		<category><![CDATA[Import]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1695</guid>
		<description><![CDATA[I&#8217;ve produced a video on how to use WebSpy Vantage to report on IronPort&#8217;s Web Security Appliance&#8217;s access log files. It is quite a detailed look at the key tasks involved in setting up and using WebSpy Vantage with IronPort WSA access logs, and is therefore divided into several parts. The videos take you through [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve produced a video on how to use WebSpy Vantage to report on IronPort&#8217;s Web Security Appliance&#8217;s access log files. It is quite a detailed look at the key tasks involved in setting up and using WebSpy Vantage with IronPort WSA access logs, and is therefore divided into several parts. The videos take you through the following activities:</p>
<ul>
<li>How to import your log files and explore the information recorded by IronPort using the Summaries screen</li>
<li>How to open the customized IronPort Report Templates and Aliases</li>
<li>How to generate reports</li>
<li>How to import your organizational structure and report on departments</li>
<li>How to setup the Web Module and publish reports</li>
</ul>
<h3><span id="more-1695"></span>PART 1: Importing log files &amp; exploring your IronPort summaries</h3>
<p>Once you have exported your IronPort access logs (see <a title="How to Import and Analyze IronPort log files" href="http://www.webspy.com.au/vendors/ironport/howto.aspx#ftp" target="_blank">http://www.webspy.com.au/vendors/ironport/howto.aspx#ftp</a>), this video takes you through importing your logs into WebSpy Vantage and analyzing data on the Summaries screen.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjMgA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjMgA" allowfullscreen="true"></embed></object></p>
<h3>PART 2: Opening the customized IronPort Templates &amp; Aliases, and running reports</h3>
<p>This video takes you through opening the IronPort-specific report templates and aliases and generating a report that provides an overview of your organization&#8217;s Internet usage.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjOAA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjOAA" allowfullscreen="true"></embed></object></p>
<h3>PART 3: Importing your Organization structure &amp; generating department reports</h3>
<p>This video shows you how to import your organizational structure into WebSpy Vantage from a directory server (such as Active Directory) using LDAP, and then generating a report that contains information on your newly imported departments.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjPAA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjPAA" allowfullscreen="true"></embed></object></p>
<h3>PART 4: Using the Web Module.</h3>
<p>This video takes you through configuring and using the WebSpy Vantage Web Module. Specifically, it takes you through the following tasks:</p>
<ul>
<li>Configuring the Web Module for Windows Authentication</li>
<li>Adding a Web Module to Vantage</li>
<li>Publishing reports to the Web Module</li>
<li>Adding permissions for a user</li>
<li>Synchronizing the Web Module</li>
<li>Using the Dynamic Reports tab</li>
</ul>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjSAA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjSAA" allowfullscreen="true"></embed></object></p>
<h3>PART 5: A quick word about tasks &amp; conclusion</h3>
<p>This video summarizes the actions taken in the previous four videos and also briefly discusses how to automate the reporting processing using scheduled tasks.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjSwA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjSwA" allowfullscreen="true"></embed></object></p>
<p>I hope this helps! Let me know if you have any questions by leaving a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/video-how-to-use-webspy-vantage-to-report-on-ironport-log-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Accessing Microsoft Forefront TMG&#8217;s Log Files (SQL Express)</title>
		<link>http://www.webspy.com.au/blogs/index.php/accessing-microsoft-forefront-tmgs-log-files-sql-express/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/accessing-microsoft-forefront-tmgs-log-files-sql-express/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 06:54:59 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[Import]]></category>
		<category><![CDATA[microsoft Forefront TMG]]></category>
		<category><![CDATA[MSFW]]></category>
		<category><![CDATA[protocols]]></category>
		<category><![CDATA[SQL Express]]></category>
		<category><![CDATA[SQL Server Configuration Manager]]></category>
		<category><![CDATA[Web Proxy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1557</guid>
		<description><![CDATA[If you need to analyze and report on Microsoft Forefront Threat Management Gateway log files, the most common stumbling block is enabling access to the default SQL Express databases that contains the firewall and web proxy log files.
The log databases are stored in an SQL Express instance named MSFW. By default these databases cannot be [...]]]></description>
			<content:encoded><![CDATA[<p>If you need to analyze and report on Microsoft Forefront Threat Management Gateway log files, the most common stumbling block is enabling access to the default SQL Express databases that contains the firewall and web proxy log files.</p>
<p>The log databases are stored in an SQL Express instance named <strong>MSFW</strong>. By default these databases cannot be accessed by a remote computer. I&#8217;d first like to say that we recommend <a title="Changing Forefront TMG's logging to W3C Text Files" href="http://technet.microsoft.com/en-us/library/cc995312.aspx" target="_blank">changing TMG&#8217;s logging to W3C text files</a>, as these logs are about 5-6 times faster to import, and you don&#8217;t need to worry about the steps below.</p>
<p>But if you need to stick with the SQL Express logging, here are the basic steps to enable access to the logs from a remote computer:<span id="more-1557"></span></p>
<h3>Enable TCP access to the MSFW instance</h3>
<p>To do this:</p>
<ol>
<li>Log into your Forefront TMG server using administrator credentials.</li>
<li>Select <strong>Start | All Programs | Microsoft SQL Server 2008 | Configuration Tools | SQL Server Configuration Manager</strong>.</li>
<li>Expand <strong>SQL Server Network Configuration</strong> and select <strong>Protocols for MSFW</strong></li>
<li>Right-click <strong>TCP/IP</strong> and select <strong>Enable</strong></li>
<li>Click <strong>OK </strong>on the Warning dialog informing you that &#8220;changes will not take effect until the service is stopped and restarted.&#8221;</li>
</ol>
<div id="attachment_1559" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/tmgconfig01_enabletpcip.png"><img class="size-medium wp-image-1559" title="Enabling TCP/IP on the MSFW instance" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/tmgconfig01_enabletpcip-300x140.png" alt="Enabling TCP/IP on the MSFW instance" width="300" height="140" /></a><p class="wp-caption-text">Enabling TCP/IP on the MSFW instance</p></div>
<h3>Set the listening Port on the MSFW instance</h3>
<p>Once TCP/IP is enabled on the MSFW instance, you need to set it to listen on port 1433</p>
<ol>
<li>Select <strong>Protocols for MSFW </strong>under SQL Server Network Configuration</li>
<li>Right-click <strong>TCP/IP</strong> and select <strong>Properties</strong>.</li>
<li>Click the <strong>IP Addresses</strong> tab and scroll to the <strong>IPAll</strong> section at the bottom of the list.</li>
<li>Change the TCP Port to <strong>1433</strong> and ensure nothing is entered in TCP Dynamic Ports (Delete the &#8216;0&#8242; value  if present). Click <strong>OK and </strong>click <strong>OK</strong> on the Warning dialog.</li>
</ol>
<div id="attachment_1561" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/tmgconfig02_setmsfwport.png"><img class="size-medium wp-image-1561" title="Setting the Port on the MSFW instance" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/tmgconfig02_setmsfwport-300x247.png" alt="Setting the Port on the MSFW instance" width="300" height="247" /></a><p class="wp-caption-text">Setting the Port on the MSFW instance</p></div>
<h3>Change the listening port on the ISARS instance</h3>
<p>The ISARS SQL instance also listens on port 1433 and this can cause connection issues. Change this instance to use port 1434:</p>
<ol>
<li>Still in SQL Server Configuration Manager, select Protocols for ISARS under SQL Server Network Configuration</li>
<li>Right-click <strong>TCP/IP</strong> and select <strong>Properties</strong>.</li>
<li>Click the <strong>IP Addresses</strong> tab and scroll to the IPAll section at the bottom of the list.</li>
<li>Change the TCP Port to <strong>1434 </strong>and ensure nothing is entered in TCP Dynamic Ports. Click <strong>OK </strong>and click <strong>OK </strong>on the Warning dialog.</li>
</ol>
<div id="attachment_1562" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/tmgconfig02_changeisarsport.png"><img class="size-medium wp-image-1562" title="Changing the port on the ISARS instance" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/tmgconfig02_changeisarsport-300x248.png" alt="Changing the port on the ISARS instance" width="300" height="248" /></a><p class="wp-caption-text">Changing the port on the ISARS instance</p></div>
<h3>Restart the Services</h3>
<p>For the above changes to take effect, you need to restart the SQL Server (ISARS) and then the SQL Server (MSFW) services in that order.</p>
<ol>
<li>Go to <strong>Start | Administrative Tools | Services</strong></li>
<li>Right-click the <strong>SQL Server (ISARS)</strong> service and select <strong>Restart</strong>.</li>
<li>Right-click the <strong>SQL Server (MSFW)</strong> service and select <strong>Restart</strong>.</li>
</ol>
<h3>Test the connection from the WebSpy machine</h3>
<p>You should now be able to connect to the MSFW databases from a remote computer. To test the connection, we recommend that you install SQL Management Studio on the machine running WebSpy and try to connect to &lt;TMGservername&gt;\MSFW, 1433 <em>(replace &lt;TMGservername&gt; with your actual server name or IP address)</em>. For example TMGServer\MSFW, 1433 or 192.168.0.10\MSFW, 1433.</p>
<p>As long as you are logged into Windows with a user account that is a local administrator on the TMG server, you should be able to connect without issue.</p>
<h3>Importing the TMG Log files into WebSpy Vantage</h3>
<p>Once you have established a connection, you can import your logs using WebSpy Vantage like so:</p>
<div id="attachment_1583" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1583" title="Importing Microsoft Forefront TMG SQL Express Log Files - Storage Name" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/06/TMGSQLe01-300x225.png" alt="Importing Microsoft Forefront TMG SQL Express Log Files Importing Microsoft Forefront TMG SQL Express Log Files - Storage Name" width="300" height="225" /><p class="wp-caption-text">Create a new Storage</p></div>
<div id="attachment_1584" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1584" title="Importing Microsoft Forefront TMG SQL Express Log Files - Select Database Connection" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/06/TMGSQLe02-300x225.png" alt="Importing Microsoft Forefront TMG SQL Express Log Files - Select Database Connection" width="300" height="225" /><p class="wp-caption-text">Select Database Connection</p></div>
<div id="attachment_1585" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1585" title="Importing Microsoft Forefront TMG SQL Express Log Files - Select Microsoft FTMG" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/06/TMGSQLe03-300x225.png" alt="Importing Microsoft Forefront TMG SQL Express Log Files - Select Microsoft FTMG" width="300" height="225" /><p class="wp-caption-text">Select the Microsoft FTMG Loader</p></div>
<div id="attachment_1587" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1587" title="Importing Microsoft Forefront TMG SQL Express Log Files - Click Add" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/06/TMGSQLe4a-300x225.png" alt="Importing Microsoft Forefront TMG SQL Express Log Files - Click Add" width="300" height="225" /><p class="wp-caption-text">Click Add</p></div>
<div id="attachment_1586" class="wp-caption aligncenter" style="width: 225px"><img class="size-medium wp-image-1586" title="Importing Microsoft Forefront TMG SQL Express Log Files - Enter Server Details" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/06/TMGSQLe04-215x300.png" alt="Importing Microsoft Forefront TMG SQL Express Log Files - Enter Server Details" width="215" height="300" /><p class="wp-caption-text">Enter TMGServer\MSFW and port 1433</p></div>
<div id="attachment_1588" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1588" title="Importing Microsoft Forefront TMG SQL Express Log Files - Successfully Imported WebProxy Logs" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/06/TMGSQLe05-300x187.png" alt="Importing Microsoft Forefront TMG SQL Express Log Files - Successfully Imported WebProxy Logs" width="300" height="187" /><p class="wp-caption-text">Successfully Imported WebProxy Logs</p></div>
<p>The screenshots above also illustrate using a database mask of *WEB* to only import the WebProxy logs. If you only want to import the Firewall logs, set the database mask to *FWS*. If you want to import both the WebProxy and Firewall logs, leave the database and table masks set to *.</p>
<p>Now that you have your log files imported, you can run a quick ad-hoc analysis on the Summaries screen or generate any of Vantage&#8217;s default web of firewall reports. M</p>
<p>Make sure you also download our <a title="Microsoft Forefront TMG Report Template and Aliases" href="http://www.webspy.com/vendors/microsoft-ftmg/FTMG-Template-and-Aliases.zip">Forefront TMG specific Aliases and report template</a>. For more information, see our <a title="How to Import and Analyze Microsoft Forefront Threat Management Gateway Log Files" href="http://www.webspy.com/vendors/microsoft-ftmg/howto.aspx" target="_blank">Forefront TMG How To page</a>.</p>
<p>If you have any questions or encounter any hurdles, please leave a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/accessing-microsoft-forefront-tmgs-log-files-sql-express/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to report on bandwidth utilization using Cisco devices</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-to-report-on-bandwidth-utilization-using-cisco-devices/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-to-report-on-bandwidth-utilization-using-cisco-devices/#comments</comments>
		<pubDate>Thu, 27 May 2010 07:59:13 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[FlowMonitor]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[ip addresses]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[netflow]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[protocols]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[Subnets]]></category>
		<category><![CDATA[utilization]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1531</guid>
		<description><![CDATA[Today I was speaking to a customer that had the following reporting request. "I would like to know how much of my bandwidth is being eaten by each protocol. I will then use this information to determine if circuit may need to be increased due to increased traffic". This customer was collecting syslog messages from a Cisco Firewall, then using WebSpy Vantage to generate reports. There's a simpler method.]]></description>
			<content:encoded><![CDATA[<p>Today I was speaking to a customer that had the following reporting request:</p>
<blockquote><p>&#8220;I would like to know how much of my bandwidth is being eaten by each protocol. I will then use this information to determine if circuit may need to be increased due to increased traffic&#8221;.</p></blockquote>
<p>This customer was collecting syslog messages from a Cisco Firewall, then using WebSpy Vantage to generate reports. In theory, this sounds like a fair plan. Unfortunately, the Cisco Firewall logs many different types of messages. Some to do with denied packets, some to do with authentication, some for vpn and so on. The information contained within each message changes. Some events include the size information that is required for any type of bandwidth assessment and some don&#8217;t. Correlating the required events to get any sort of accurate &#8216;bandwidth&#8217; representation is a bit of a nightmare.</p>
<p>Fortunately, there&#8217;s a simpler method. <span id="more-1531"></span>If you search the Cisco website or the Internet for bandwidth utilization reporting, you&#8217;ll no doubt be pointed in the direction of NetFlow.</p>
<blockquote><p>NetFlow is a network protocol developed by Cisco Systems to run on Cisco IOS-enabled equipment for collecting IP traffic information [Source Wikipedia <a href="http://en.wikipedia.org/wiki/Netflow" target="_blank">http://en.wikipedia.org/wiki/Netflow</a>]</p></blockquote>
<p>There are a couple of commands to enter on your router to turn NetFlow on, and then you just need a NetFlow collector to receive the Netflow information and generate reports.</p>
<p>Fortunately WebSpy has developed a little tool called <a title="WebSpy FlowMonitor" href="http://www.webspy.com/products/addons/flowmonitor/default.aspx" target="_blank">FlowMonitor</a> that collects the Netflow information and writes a log file that can then be imported into <a title="WebSpy Vantage" href="http://www.webspy.com/products/vantage/default.aspx" target="_blank">WebSpy Vantage</a> and reported on.</p>
<div style="float: right; margin-left: 10px;">
<div id="attachment_1547" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/management_console.gif"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/management_console-300x222.gif" alt="The FlowMonitor Management Console" title="FlowMonitor Management Console" width="300" height="222" class="size-medium wp-image-1547" /></a><p class="wp-caption-text">The FlowMonitor Management Console</p></div>
</div>
<p>Once your FlowMonitor logs are imported into WebSpy Vantage, you can  run the default <a title="Cisco Netflow Report using WebSpy FlowMonitor" href="http://www.webspy.com/resources/samplereports/Vantage/FlowMonitor%20Analysis.html" target="_blank">FlowMonitor report</a> to see the size of traffic flowing  between IP addresses, subnets, router interfaces or protocols.  Alternatively you can create your own custom reports to see exactly what  you want to see.</p>
<p>NetFlow doesn&#8217;t record usernames or URLs so it&#8217;s not great for reporting on the web sites your users are visiting, but it is great for network administration and trouble shooting. Identify chatty IP addresses, protocols that are chewing too much bandwidth, the times throughout the day when incoming or outgoing links become heavily utilized and so on.</p>
<p>For information on how to configure your router and deploy FlowMonitor,  see the <a title="FlowMonitor Installation and User  Guide" href="http://www.webspy.com/resources/productdoco/WebSpyFlowMonitor1InstallationAndUsersGuide.pdf" target="_blank">FlowMonitor  Installation and User Guide</a>. You can also download a <a title="FlowMonitor Free Trial" href="http://www.webspy.com/products/addons/flowmonitor/default.aspx" target="_blank">free trial here</a>.</p>
<p>FlowMonitor is a handy little tool. Ask your friendly WebSpy account manager about it today!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-to-report-on-bandwidth-utilization-using-cisco-devices/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How WebSpy Vantage uses your CPUs</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-webspy-vantage-uses-your-cpus/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-webspy-vantage-uses-your-cpus/#comments</comments>
		<pubDate>Fri, 21 May 2010 07:02:32 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[cpu]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[Import]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[system resources]]></category>
		<category><![CDATA[templates]]></category>
		<category><![CDATA[utilization]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1520</guid>
		<description><![CDATA[I’m frequently asked how WebSpy Vantage utilizes a systems CPU resources. Sometimes you may notice Vantage utilizing 100% of your machine's CPU power, and other times it will be hardly touched. So here is an overview of how the software works internally so you can understand when your CPUs will and won’t be pushed.]]></description>
			<content:encoded><![CDATA[<p>I’m frequently asked how WebSpy Vantage utilizes a systems CPU resources. Sometimes you may notice Vantage utilizing 100% of your machine&#8217;s CPU power, and other times it will be hardly touched. So here is an overview of how the software works internally so you can understand when your CPUs will and won’t be pushed.<span id="more-1520"></span></p>
<p>Vantage uses multiple threads to perform certain tasks. As general rule, the more threads being used simultaneously, the higher the CPU utilization. There are a few situations where Vantage uses multiple threads simultaneously:</p>
<h3>CPU usage when importing log files</h3>
<p>When importing more than one log file, each log will be imported with a separate thread. As CPU usage increases when more threads are used, importing a single log file won’t push your CPU, but importing a folder full of logs will.</p>
<h3>CPU usage when generating reports</h3>
<p>CPU performance can also be affected by the structure the report you are running. Report templates have what we call ‘Nodes’ in them. You can go into a report template, right-click | add node. Think of each node as an SQL query. When generating a report, each node gets processed in a separate thread, and if the nodes are ‘at the same level’ they get processed at the same time.  Here’s a screenshot showing what I mean by nodes at the same level.</p>
<div id="attachment_1521" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/image001.png"><img class="size-medium wp-image-1521" title="A report template with two 'levels' of nodes" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/05/image001-300x170.png" alt="A report template with two 'levels' of nodes" width="300" height="170" /></a><p class="wp-caption-text">A report template with two &#39;levels&#39; of nodes</p></div>
<p>The three ‘red’ nodes will be processed at the same time, and then the three ‘green’ nodes will be processed at the same time. The green nodes won’t be processed until the red nodes have been processed. The more nodes being processed at the same time increases the number of simultaneous threads and the amount of CPU being used.</p>
<h3>CPU usage when filtering reports</h3>
<p>CPU usage is also affected by the number of records being processed from your storage. If you are running a report on your entire storage with no filters, then Vantage will be pushing all records in your storage through the reporting engine. If you run the same report but with a filter for a specific user, then Vantage will seek through the records in the storage until it finds a record for that user, then push that record through the reporting engine. This results in a ‘trickle’ of records being pushed through the reporting engine so it doesn’t get a chance to really push your CPUs.</p>
<p>A filter that excludes a lot of information that exists in your storage is the most common reason for low CPU utilization while running a report.</p>
<h3>In Short</h3>
<p>The number of logs, report template structure and filters can all have an effect on the way Vantage utilizes your CPUs.</p>
<p>We also have some exciting ideas on our roadmap to ensure Vantage utilizes as many CPUs as you can throw at it. Until then, I hope the above information helps you understand when and why your CPU usage will and won&#8217;t be pushed.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-webspy-vantage-uses-your-cpus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.43</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/#comments</comments>
		<pubDate>Thu, 20 May 2010 06:45:45 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Astaro]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[BlueCoat]]></category>
		<category><![CDATA[ClearSwift]]></category>
		<category><![CDATA[dynamic reports]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[microsoft Forefront TMG]]></category>
		<category><![CDATA[NetAsq]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1511</guid>
		<description><![CDATA[We've just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module. This is a great update for Vantage Ultimate users as we've introduced a new feature/tab into the Web Module called 'Dynamic Reports'.

Here's the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module.</p>
<p>This is a great update for Vantage Ultimate users as we&#8217;ve introduced a new feature/tab into the Web Module called &#8216;Dynamic Reports&#8217;.</p>
<p>If you&#8217;re publishing the same report to the Web Module each day, you can use the Dynamic Reports tab to select a date range and a department (or whatever organizational groups you have defined) and the Web Module will collate all the daily reports that match that filter into one report. This allows you to report on entire week, month or year by simply &#8216;reporting on reports&#8217;, rather than reporting months of raw storage data.</p>
<p>Here&#8217;s the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).</p>
<p><strong>Application Changes</strong></p>
<ul>
<li>Added Dynamic Reports feature to the Web Module.</li>
<li>Rewrote the Web Module transfer protocol. New protocol adds version checking, connection checking, and integrity checking for high latency environments.</li>
<li>Purge data from storage task no longer prevents importing new hits when all data is removed from an input within a storage.</li>
<li>IPv6 addresses now show IPv4-mapped addresses as plain IPv4 addresses in summaries.</li>
<li>IPv6 and IPv4 addresses are now freely interchangable in filter expressions.</li>
<li>Fixed IPv6 drilldowns on the Summaries screen</li>
<li>SQL inputs can now be resumed from the previous position. Previously any input that was partially imported would be skipped when importing new hits.</li>
<li>Template-based analysis has been fixed, no longer results in blank/non-existent analysis.</li>
<li>Added new string manipulation functions to expression language; Contains, StartsWith, EndsWith, IndexOf.</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>Astaro: Now checks that the ID field is present in a line before attempting to read it.</li>
<li>Barracuda Web Filter: Added this format to replace Spy Filter.</li>
<li>BlueCoat Proxy SG W3C: Added support for gmttime, timestamp, x-bluecoat-surfcontrol-is-denied and x-bluecoat-transaction-id.</li>
<li>ClearSwift: Added a new loader group for ClearSwift that includes the MimeSweeper loaders</li>
<li>ClearSwift SECURE Web Gatway: Now supported with the Web Appliance loader</li>
<li>Clearswift Web Appliance: User summary displays Source IP if Username is blank.</li>
<li>IronPort WSA: Fixed memory usage issues.</li>
<li>Microsoft FTMG: Added category name lookup to SQL loader.</li>
<li>Microsoft FTMG: No longer fails to import lines where the rule field contains square brackets.</li>
<li>Microsoft FTMG: URL Category field is now a string instead of an integer. Added URL Categorization Reason field.</li>
<li>Microsoft FTMG: Fixed memory usage issues.</li>
<li>Microsoft IIS W3C: No longer hangs or crashes when loading a file that isn&#8217;t IIS W3C.</li>
<li>NetAsq: Added support for srcname field. The Username summary is populated with user first, and then srcname if user is blank. The User summary is also now populated with Source IPs if the Username summary is blank.</li>
</ul>
<p>To update WebSpy Vantage, simple select Tools | Check for updates.</p>
<p>To update the Web Module, login to the Web Module server, right-click the WebSpy system tray icon, and select Check for updates.</p>
<p>As always, please <a title="Contact WebSpy" href="http://www.webspy.com/about/contact.aspx" target="_blank">contact us</a> if you have any issues or questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Module Update Errors and Workaround</title>
		<link>http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/#comments</comments>
		<pubDate>Wed, 14 Apr 2010 05:53:57 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[exception]]></category>
		<category><![CDATA[installation]]></category>
		<category><![CDATA[location]]></category>
		<category><![CDATA[System.IO.FileLoadException]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1340</guid>
		<description><![CDATA[We have just issued an automatic update for the Vantage range of products, including Vantage Ultimate and the Web Module.

Unfortunately there are two issues with the Web Module auto update process. Everyone on a 64 bit operating system machines will encounter issue #1 (Unable to locate installation location), and some of you may encounter issue #2 (System.IO.FileLoadException).]]></description>
			<content:encoded><![CDATA[<p>We have just issued an automatic update for the Vantage range of products, including Vantage Ultimate and the Web Module.</p>
<p>Unfortunately there are two issues with the Web Module auto update process. Everyone on a 64 bit operating system will encounter issue #1 (Unable to locate installation location), and some of you may encounter issue #2 (System.IO.FileLoadException).</p>
<p>This article describes the errors and how to work around them to successfully update the Web Module.<span id="more-1340"></span></p>
<h3>Issue #1</h3>
<p>The usual process to update your Web Module is to log into your Web Module server, right-click the WebSpy system tray icon and select &#8216;Check for updates&#8217;.</p>
<p>If you do this on a 64 bit operating system, you will receive the following error:</p>
<div id="attachment_1341" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/04/unabletolocateinstallationlocation.png"><img class="size-medium wp-image-1341" title="Unable to locate installation location" src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/04/unabletolocateinstallationlocation-300x108.png" alt="Web Module Updater error: Unable to locate installation location" width="300" height="108" /></a><p class="wp-caption-text">Web Module Updater error: Unable to locate installation location</p></div>
<p>You can fix this issue by clicking Yes, and specifying the Web Module&#8217;s installation location, which is usually somewhere under c:\inetpub\wwwroot (or just c:\inetpub\wwwroot if you didn&#8217;t specify a virtual directory when installing).</p>
<p>This will allow the updater to continue and you will be prompted to download and install the latest update.</p>
<h3>Issue #2</h3>
<p>Unfortunately, you may encounter another error during the update installation. The text of the error will be something along the lines of:</p>
<blockquote><p>System.IO.FileLoadException: Could not load file or assembly &#8216;ICSharpCode.SharpZipLib, Version=0.84.0.0, Culture=neutral, PublicKeyToken=1b03e6acf1164f73&#8242; or one of its dependencies. The located assembly&#8217;s manifest definition does not match the assembly reference. (Exception from HRESULT: 0&#215;80131040)</p></blockquote>
<h3>Work Around</h3>
<p>We are currently working on solutions to both of these issues. In the mean time, here is a work around to install the update. On the Web Module server:</p>
<ol>
<li>Download this file:<br />
<a title="WebSpy Vantage Web Module 2.2.0.10" href="http://update.webspy.com/autoupdate/files/vantagewebmodule/vantagewebmodule2.2.0.18.zip" target="_blank"> http://update.webspy.com/autoupdate/files/vantagewebmodule/vantagewebmodule2.2.0.18.zip</a></li>
<li>Stop IIS (See instructions below).</li>
<li>Right-click the WebSpy system tray icon and click <strong>Exit</strong>.</li>
<li>Backup your existing Web Module installation by copying everything in your Web Module&#8217;s installation folder (usually under c:\inetpub\wwwroot (or just  c:\inetpub\wwwroot if you didn&#8217;t specify a virtual directory when  installing) into a completely separate location (i.e. don&#8217;t keep it in a sub-folder).</li>
<li>Extract the downloaded zip file to your web module&#8217;s installation folder. Overwrite all the existing files.</li>
<li>Start IIS (see instructions below).</li>
</ol>
<p>Your Web Module will now be updated to the latest version.</p>
<h3>Stopping and Starting IIS</h3>
<p>In IIS Manager (Start | Control Panel | Administrative Tools | Internet Information Services (IIS)) , right-click the site you want to start or stop, and click <strong>Start</strong> or <strong>Stop</strong></p>
<p>We sincerely apologize for the inconvenience and will hopefully have a solution out soon. If you have any problems with the process above, please contact support at webspy dot com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Soho Alpha Release &#8211; Issues and Workarounds</title>
		<link>http://www.webspy.com.au/blogs/index.php/soho-alpha-release-issues-and-workarounds/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/soho-alpha-release-issues-and-workarounds/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 06:28:06 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[WebSpy Soho]]></category>
		<category><![CDATA[cpu]]></category>
		<category><![CDATA[dashboard]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[errors]]></category>
		<category><![CDATA[issues]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[restart]]></category>
		<category><![CDATA[service]]></category>
		<category><![CDATA[soho]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1326</guid>
		<description><![CDATA[It’s been a crazy few weeks but we’ve finally managed to get the first release of WebSpy Soho out the door.

It is our intention to keep our Alpha testers up to date with our ongoing development. Right now, I’d like to inform you about some issues experienced by a handful of testers and how to go about resolving them.]]></description>
			<content:encoded><![CDATA[<p>It’s been a crazy few weeks but we’ve finally managed to get the first release of WebSpy Soho out the door.</p>
<p>For those that don’t know what Soho is all about, check out this video:<span id="more-1326"></span><br />
<object width="480" height="300" data="http://blip.tv/play/hLYlgdKEQwI" type="application/x-shockwave-flash"><param name="src" value="http://blip.tv/play/hLYlgdKEQwI" /><param name="allowfullscreen" value="true" /></object></p>
<p>Soho is a dashboard application that displays download and upload traffic statistics for each computer in your network. If you haven&#8217;t yet tried Soho, please give it a go and <a title="WebSpy Soho Download Page" href="http://www.webspy.com.au/products/soho/download.aspx" target="_blank">download it here</a>.</p>
<p>It is our intention to keep our Alpha testers up to date with our ongoing development. Right now, I’d like to inform you about some issues  experienced by a handful of testers and how to go about resolving them.</p>
<h2>Learn to restart the Soho Agent</h2>
<p>First of all, one of the handiest things we can tell you right now is  how to restart the Soho Agent. This single step is resolves 99% of all  Soho issues, at least temporarily. If these steps seem too complicated,  rebooting your PC also has the same effect.</p>
<p>To restart the Soho Agent on Windows:</p>
<ol>
<li>Launch the Services Console by going to Control Panel |  Administrative Tools | Services. Or if you like handy short cuts, try  Start | Search (or Run), Type ‘services.msc’ (without the quotes) and  press enter.</li>
<li> Right-click the “WebSpy Soho Agent” service and select Restart. If  you get a ‘time out’ error message or warning, ignore it and right-click  the service again and select Start.</li>
</ol>
<p>To restart the Soho Agent on Mac OS:</p>
<ol>
<li>Open the terminal from /Applications/Utilities/Terminal</li>
<li> Type sudo launchctl stop “WebSpy Soho Agent”</li>
<li> Enter your user password if requested.</li>
<li> Wait about 5 seconds.</li>
<li> Type sudo launchctl start “WebSpy Soho Agent”</li>
<li> Again, enter your user password if requested</li>
</ol>
<p>OK, now you have the skills, here are the issues and work-arounds:</p>
<h2>100% CPU usage after sleep or hibernate</h2>
<p>Some users reported Soho’s impressive ability to consume 100% of  their CPU when their computer wakes from sleep or hibernation. A few  users experienced a slow and sluggish PC, and uninstalled Soho  immediately.</p>
<p>If you’re looking for the Soho process in Windows Task Manager you  will not see it until you click the Show processes from all users button  (or checkbox in XP). This is because the Soho Agent runs under the  System user account in order for it to run, no matter who is logged onto  the PC.</p>
<p>From here you can end the WebSpy.Soho.Agent.exe process and  everything should return to normal. You can then restart the “WebSpy  Soho Agent” to get Soho working again (see steps above).</p>
<p>We believe we have fixed this and are in the middle of some final  testing. All going well, we should have a new build ready for you very  soon. In the mean time, you may like to disable sleep and hibernation in  your PC’s power options.</p>
<h2>Soho doesn’t install on Mac OS 10.5??</h2>
<p>Our first Alpha release did not install on Mac OS 10.5 (Leopard).  This was due to a silly checkbox in our packaging system not being  checked. We’ve checked the checkbox and uploaded a new build to our web  site. You can download it from here:<br />
<a title="WebSpy Soho Download Page" href="http://www.webspy.com.au/products/soho/download.aspx" target="_blank"> http://www.webspy.com.au/products/soho/download.aspx</a></p>
<p>Note: Soho will only install on Mac OS 10.5 (Leopard) and 10.6 (Snow  Leopard). Versions 10.4 (Tiger) and below are not supported.</p>
<h2>All computers disappear from the Current Activity chart except the  local computer</h2>
<p>Sometimes all computers will disappear from the Current Activity  chart leaving your local computer all by itself. This happens when the  communication between Soho Agents becomes jammed. You can usually  resolve the issue by restarting the Soho Agent on your local computer  (see steps below). If this doesn’t work, restart the Agents on all other  computers running Soho. We are currently working on a fix for this  issue.</p>
<h2>The Soho User Interface is completely blank</h2>
<p>If there is no information in the Total, Current Activity or History  chart, this is because the Soho Agent has stopped running. Reasons for  this may vary, so please let us know if this is regularly occurring.  Restarting your agent usually resolves the issue (see steps above).</p>
<h2>Feedback</h2>
<p>Thank you to everyone that has submitted feedback so far.</p>
<p>Just a reminder to please let us know if your network card works or  doesn’t work with Soho on this page:<br />
<a title="Supported Network Cards" href="../../products/soho/supportednics.aspx" target="_blank">http://www.webspy.com.au/products/soho/supportednics.aspx</a></p>
<p>You may also like to review the current list of features and bugs and  vote them up or down at:<br />
<a title="WebSpy Soho Uservoice Page" onclick="javascript:pageTracker._trackPageview('/outbound/article/webspysoho.uservoice.com');" href="http://webspysoho.uservoice.com/" target="_blank">http://webspysoho.uservoice.com/</a></p>
<p>There is also a dedicated Soho Alpha Feedback thread in our forums  at:<br />
<a title="WebSpy Soho Forums" href="http://www.webspy.com.au/forums/viewtopic.php?f=8&amp;t=12" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=8&amp;t=12</a></p>
<p>We will let you know when fixes are available to the above issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/soho-alpha-release-issues-and-workarounds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.29 &#8211; New Fields for IronPort</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 06:55:01 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[bytes received]]></category>
		<category><![CDATA[bytes sent]]></category>
		<category><![CDATA[fields]]></category>
		<category><![CDATA[group]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[WebSpy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1282</guid>
		<description><![CDATA[We have just added support for the 'Group' field in IronPort's access logs. You can add this field to your logs by adding %g in the 'Custom Fields' edit box. We have also added support for the custom fields Body Request Size and Body Response Size.]]></description>
			<content:encoded><![CDATA[<p>We have just added support for the &#8216;Group&#8217; field in IronPort&#8217;s access logs. You can add this field to your logs by adding %g in the &#8216;Custom Fields&#8217; edit box (on your IronPort WSA appliance  under System Administration | Log Subscriptions | accesslogs).</p>
<p>When imported into WebSpy Vantage, the result is shown in a new summary called &#8216;Group&#8217; which you can add to your reports.<span id="more-1282"></span></p>
<p><del datetime="2010-03-16T01:30:47+00:00">We also added support for the custom fields Bytes Sent and Bytes Received. Due to the absence of a header in the IronPort access log, Bytes Received and Bytes Sent fields must both be present to be detected, and the Received field must precede the Sent field.</del></p>
<p>We also added support for the custom fields Request Body Size and Response Body Size. These fields can be included in your access log by adding %q (Request body size) and %b (Response body size)  in the &#8216;Custom Fields&#8217; edit box. Due to the absence of a header in the IronPort access log, Request Body Size and Response Body Size fields must both be present to be detected, and the Request field must precede the Response field.</p>
<p><del datetime="2010-03-16T01:30:47+00:00">We&#8217;ve also noticed that the values in the Bytes Sent and Bytes Received fields do not necessarily add up to the value logged for &#8216;Size&#8217;. We&#8217;re discussing this issue with our friends at IronPort and we will hopefully post a solution or explanation soon.</del>.<br />
The information we first received about these fields indicated they represented Bytes Sent and Bytes Received. This is the way they are represented in the builds below (2.2.0.29). We will release a new build soon, with the field names changed to Request body size and Response body size. Body size is different to bytes sent/received as it does not include bytes from packet headers etc.</p>
<p>We&#8217;re yet to issue an automatic update for the Vantage applications, so in the mean time you can download the latest builds here:</p>
<p>Vantage Ultimate:<br />
<a title="Vantage Ultimate 2.2.0.29" href="ftp://ftp.webspy.com/webspy/Builds/VantageUltimate2.2.0.29.zip" target="_blank"> ftp://ftp.webspy.com/webspy/Builds/VantageUltimate2.2.0.29.zip</a></p>
<p>Vantage Web Module:<br />
<a href="ftp://ftp.webspy.com/webspy/Builds/VantageWebModule2.2.0.8.exe">ftp://ftp.webspy.com/webspy/Builds/VantageWebModule2.2.0.8.exe</a></p>
<p>Vantage Giga:<br />
<a title="Vantage Giga 2.2.0.27" href="ftp://ftp.webspy.com/webspy/Builds/VantageGiga2.2.0.29.zip" target="_blank">ftp://ftp.webspy.com/webspy/Builds/VantageGiga2.2.0.29.zip</a></p>
<p>Vantage Premium:<br />
<a title="Vantage Premium 2.2.0.29" href="ftp://ftp.webspy.com/webspy/Builds/VantagePremium.2.0.29.zip" target="_blank">ftp://ftp.webspy.com/webspy/Builds/VantagePremium2.2.0.29.zip</a></p>
<p><strong>To apply the Vantage update</strong>, close Vantage and extract the downloaded file into Vantage’s installation folder (Usually c:\Program Files\WebSpy\Vantage &lt;flavour&gt; 2.2). Overwrite the existing files.</p>
<p><strong>To apply the Web Module update</strong>, uninstall the Vantage Web Module from Add/Remove Programs (Programs and Features in Windows 7/Server 2008), then run the downloaded exe file, making sure you specify the same server, virtual directory and data location that your Web Module was previously using.</p>
<p>We will be releasing this as a public auto-update soon. Let us know if you have any issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.27 &#8211; Fix for Microsoft FTMG SQL Import</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22027-fix-for-microsoft-ftmg-sql-import/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22027-fix-for-microsoft-ftmg-sql-import/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 15:58:13 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[Import]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MSFW]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Specified Cast Invalid]]></category>
		<category><![CDATA[SQL Express]]></category>
		<category><![CDATA[Threat Management Gateway]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1272</guid>
		<description><![CDATA[Our support for Microsoft Forefront Threat Management Gateway is quite new and we’ve just fixed a couple of issues that we haven’t yet released as a public update yet. In particular, this update fixes the "specified cast invalid error" that occurs when importing the Web Proxy database logs.]]></description>
			<content:encoded><![CDATA[<p>Our support for Microsoft Forefront Threat Management Gateway is quite new and we’ve just fixed a couple of issues in build 2.2.0.27. In particular, this update fixes the &#8220;specified cast invalid error&#8221; that occurs when importing the Web Proxy database logs.</p>
<p>Check your version in Help | About. If you are running 2.2.0.27 or above, then you already have this update. If not, make sure you update to your software by selecting <strong>Tools | Check for updates.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22027-fix-for-microsoft-ftmg-sql-import/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>8 Reasons NOT to Use Microsoft Forefront TMG&#8217;s Reporting</title>
		<link>http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 06:48:39 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[customize]]></category>
		<category><![CDATA[drilldowns]]></category>
		<category><![CDATA[Filtering]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[limitations]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[productivity]]></category>
		<category><![CDATA[report distribution]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[secure report distribution]]></category>
		<category><![CDATA[sub-domains]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[TMG Reporting]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1181</guid>
		<description><![CDATA[I've been having a look through the reporting functionality included in Microsoft Forefront Threat Management Gateway to find that not much has changed from ISA Server 2006. There is some new information regarding the newly implemented URL categorization and threat management technology, but there is very little flexibility or customization for those with reporting requirements beyond general overviews cluttered with irrelevant information. Here is what I consider to be the 8 main limitations of Microsoft Forefront TMG's reporting functionality.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been having a look through the reporting functionality included in Microsoft Forefront Threat Management Gateway to find that not much has changed from ISA Server 2006. There is some new information regarding the newly implemented URL categorization and threat management technology, but there is very little flexibility or customization for those with reporting requirements beyond general overviews cluttered with irrelevant information.<span id="more-1181"></span></p>
<p>Here&#8217;s a quick video outlining some of the differences between TMGs Reporting, and what can be achieved using WebSpy Vantage. The video does not illustrate all the limitations outlined below, so please read on.<br />
<object width="400" height="255" data="http://blip.tv/play/hLYlgcLyGAA" type="application/x-shockwave-flash"><param name="src" value="http://blip.tv/play/hLYlgcLyGAA" /><param name="allowfullscreen" value="true" /></object></p>
<h2>Whats is in the Forefront TMG report?</h2>
<p>The default TMG report contains the following sections</p>
<ul>
<li>Summary</li>
<li>Web Usage</li>
<li>Application Usage</li>
<li>Traffic and Utilization</li>
<li>Security</li>
<li>Malware Protection</li>
<li>URL Filtering</li>
<li>Network Inspection System</li>
</ul>
<p>Each section contains overviews such as &#8216;Top users&#8217; and &#8216;Top Sites&#8217;.</p>
<p>If your reporting requirements can be satisfied with these overviews &#8211; that&#8217;s great! Unfortunately, when you start thinking about what system administrators and other people in your organization actually need to make informed decisions, this report is quite limiting.</p>
<h1>The 8 Limitations of Microsoft Forefront TMG&#8217;s Reporting</h1>
<p>Here is what I consider to be the<strong> </strong>8 main limitations of Microsoft Forefront TMG&#8217;s reporting functionality.</p>
<h2>1. No Drilldowns</h2>
<p>Want to see the sites that the top 5 users accessed? Want to see the users that downloaded the most traffic from youtube? These are fairly standard reporting requirements that simply cannot be achieved using the inbuilt TMG reporting.</p>
<p>WebSpy Vantage lets you either interactively drilldown into a user or site, or produce a regular report that includes further details about what your top users have actually been up to.</p>
<h2>2. No Filtering</h2>
<p>When you generate a report in TMG, you can only filter the report by a date range. There is no way to filter out anonymous (unauthenticated) traffic or exclude traffic coming from advertising servers (such as doubleclick and 2mdn.net) that tend to dominate most of the top 10 sites.</p>
<p>This can easily be achieved using WebSpy&#8217;s software. Check out my<a href="http://www.webspy.com.au/blogs/index.php/how-to-remove-clutter-from-your-web-reports/" target="_blank"> video on how to remove clutter from your web reports</a>.</p>
<h2>3. No Customization</h2>
<p>Customization of each overview in the TMG report is limited to the number of items to show (e.g. top 5 or top 50 users), and the sort order (Incoming Bytes, Outgoing Bytes, Requests and Total Bytes).</p>
<p>What about the time a user spent browsing the web, or the number of users that visited a specific site? There is no way to add custom columns such as total browsing time, average session time, or number of users/sites/IPs to the report tables.</p>
<p>Or say you simply want to change your top users chart from a bar to pie to easily see the percentage used. Nope sorry!</p>
<p>If you do make one of the two available customizations in a TMG report, you then get the annoying Apply / Discard message to save changes to the configuration database.</p>
<p>All of these customizations can be achieved using WebSpy Vantage, and it doesn&#8217;t touch your TMG server to apply a change to a report.</p>
<h2>4. Limited Report Distribution</h2>
<p>When you generate a report, you get the option to email it to a specific email address. What if you would like to create a report for every department, and then email it to the managers of each department? Or better yet, host the report on a secure web server where department managers can log in and view their reports?</p>
<p>WebSpy Vantage Ultimate comes with a secure &#8216;Web Module&#8217; specifically for this purpose and managers still receive a link to the report via email.</p>
<h2>5. Cluttered &#8216;Top Sites&#8217; List</h2>
<p>The &#8216;Top sites&#8217; list can become particularly cluttered due to the inclusion of sub-domains. I don&#8217;t want to mentally add up the size values from farm1.static.flickr.com, farm2.static.flickr.com, and farm3.static.flicr.com &#8211; I just want to know how much was downloaded from flickr.com.</p>
<p>This is compounded by the inability to exclude sites that are merely placing advertising banners on the actual sites users are visiting (as mentioned in the &#8216;No Filtering&#8217; limitation above).</p>
<p>WebSpy Vantage breaks URLs down into separate components and lets you analyze each part separately. Look at the <strong>Site Domains</strong> summary to remove sub-domains and see <em>only </em>flickr.com. Or perhaps you want to see the keywords a user entered into search engines like Google? Or perhaps the top pages accessed within a website? No problem. Just include the <strong>Site Keywords</strong> or <strong>Site Resource</strong> summaries in your Vantage reports.</p>
<h2>6. No Grouping or Aliasing</h2>
<p>There is no way to group users into departments or locations, or IP addresses into subnets, or extensions such as .html, .pdf or .exe into file types. The ability to group and represent raw log data in more meaningful ways, as offered by WebSpy Vantage, can increase the value of a report tremendously.</p>
<h2>7. No Productivity Assessment</h2>
<p>One of the major features introduced in TMG since ISA Server 2006 is the included URL categorization technology.</p>
<p>Although the TMG report gives you an overview of the categories that have been visited, the report does not use this information to display a productivity assessment for your users.</p>
<p>WebSpy Vantage not only provides this assessment, but also the ability to customize the categories that are deemed productive as this can vary wildly depending on the industry and organization.</p>
<h2>8. Not browser independent</h2>
<p>This is a minor limitation that can be a major annoyance. The report that TMG produces is a HTML report that only displays correctly in Internet Explorer. As Forefront TMG is a Microsoft product, this is not exactly surprising, but still very annoying if IE is not your default browser.</p>
<h2>How to get awesome reports from Forefront TMG</h2>
<p>If you have had personal experience with any of the above limitations, you&#8217;ve probably been hunting for an alternative solution. I strongly recommend checking out the <a title="WebSpy Vantage" href="http://www.webspy.com/products/vantage/default.aspx" target="_blank">WebSpy Vantage</a> range of products, and if you would like secure report distribution via the &#8216;Web Module&#8217;, <a title="Vantage Ultimate" href="http://www.webspy.com/products/vantage/ultimate/vantageultimate.aspx" target="_blank">Vantage Ultimate</a> is what you are after.</p>
<p>If you agree or disagree with anything in this article, I encourage you to leave your thoughts in the comments.</p>
<p>Cheers!</p>
<p>Scott</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Microsoft TMG and UAG Released! What is the difference?</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-tmg-and-uag-released-what-is-the-difference/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-tmg-and-uag-released-what-is-the-difference/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 07:31:02 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Migrating]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Threat Management Gateway]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[UAG]]></category>
		<category><![CDATA[Unified Access Gateway]]></category>
		<category><![CDATA[Upgrading]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1032</guid>
		<description><![CDATA[Most of our customers using Microsoft ISA server are probably aware by now that Microsoft have released the new version of ISA server, which is now re-branded as Microsoft Forefront Threat Management Gateway (TMG). In addition to this, Microsoft has also re-branded its Internet Access Gateway (IAG) to Unified Access Gateway (UAG).

If you&#8217;re confused, Derek [...]]]></description>
			<content:encoded><![CDATA[<p>Most of our customers using Microsoft ISA server are probably aware by now that Microsoft have released the new version of ISA server, which is now re-branded as <strong>Microsoft Forefront Threat Management Gateway (TMG)</strong>. In addition to this, Microsoft has also re-branded its Internet Access Gateway (IAG) to Unified Access Gateway (UAG).<br />
<span id="more-1032"></span><br />
If you&#8217;re confused, Derek Seaman has a great blog post that clears up some of the confusion around ISA/TMG/IAG/UAG at <a href="http://derek858.blogspot.com/2009/05/isa-vs-tmg-vs-iag-vs-uag-are-you.html" target="_blank">http://derek858.blogspot.com/2009/05/isa-vs-tmg-vs-iag-vs-uag-are-you.html</a></p>
<h3>TMG or UAG? What is the difference?</h3>
<p>TMG is an<strong> outgoing proxy</strong> that protects your internal users from malware, viruses and the like. TMG generates some great web proxy log files to import into WebSpy Vantage allowing you to monitor where your users are going on the Internet, how much they&#8217;re downloading etc.  TMG, unlike ISA, now has deep packet inspection for HTTPS traffic, plus a bunch of other <a href="http://www.microsoft.com/forefront/threat-management-gateway/en/us/whats-new.aspx">new features</a>.</p>
<p>UAG is an <strong>incoming proxy</strong> that provides employees, partners and vendors secure remote access to corporate resources such as Outlook Web Access (OWA) and Sharepoint (MOSS). It utilizes the TMG engine, but this is mainly just to protect the UAG server (more on this topic here <a title="About TMG and UAG - what is supported and what is not" href="http://technet.microsoft.com/en-us/library/ee522953.aspx" target="_blank">http://technet.microsoft.com/en-us/library/ee522953.aspx</a>).</p>
<p>TMG can also publish your OWA and MOSS sites, but this is no longer recommended by Microsoft. They recommend using a dedicated UAG server to perform this function.</p>
<h3>Upgrading to TMG</h3>
<p>If you&#8217;re thinking about migrating your ISA server (2004 or 2006) to TMG, you may like to check out this migration guidance video with Mohit Saxena (Senior Technical Lead) and Jim Harrison (Program Manager). <a href="http://edge.technet.com/Media/ISA-to-TMG-Migration-Guidance/" target="_blank">http://edge.technet.com/Media/ISA-to-TMG-Migration-Guidance/</a></p>
<p style="text-align: center;">
<div id="attachment_1043" class="wp-caption aligncenter" style="width: 310px"><a href="http://edge.technet.com/Media/ISA-to-TMG-Migration-Guidance/" target="_blank"><img class="size-medium wp-image-1043 " title="Microsoft Forefront TMG Migration Video" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/12/microsofttmgmigrationvideo-300x170.png" alt="Microsoft Forefront TMG Migration Video" width="300" height="170" /></a><p class="wp-caption-text">Microsoft Forefront TMG Migration Video</p></div>
<h3>Reporting on TMG</h3>
<p>If you&#8217;re using TMG at the moment, we invite you to analyze your web proxy and/or firewall logs using WebSpy Vantage and tell us what you think!  <a href="http://www.webspy.com/products/vantage/default.aspx" target="_blank">Download your copy of WebSpy Vantage here</a>, and import your logs using the Microsoft FTMG format:</p>
<div id="attachment_596" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg.png"><img class="size-medium wp-image-596" title="Microsoft Forefront Threat Management Gateway" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg-300x225.png" alt="Microsoft Forefront Threat Management Gateway" width="300" height="225" /></a><p class="wp-caption-text">Microsoft Forefront Threat Management Gateway</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-tmg-and-uag-released-what-is-the-difference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Do I Transfer Reports to a Different User in the Web Module?</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-do-i-transfer-reports-to-a-different-user-in-the-web-module/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-do-i-transfer-reports-to-a-different-user-in-the-web-module/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 03:40:57 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[attributed user]]></category>
		<category><![CDATA[changing users]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[distinquished name]]></category>
		<category><![CDATA[Permissions]]></category>
		<category><![CDATA[Transfer reports]]></category>
		<category><![CDATA[unique id]]></category>
		<category><![CDATA[user id]]></category>
		<category><![CDATA[Vantage Web Module.Reports]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=988</guid>
		<description><![CDATA[Today I was asked how to transfer one report in the web module to a different user. The obvious reason for this is when someone leaves your company, the reports they had access to need to be transfered to the new person taking over their role. Unfortunately there’s not an easy way to do this via the user interface yet, but it is a planned feature.

In the mean time, you can do it by editing an XML file manually.]]></description>
			<content:encoded><![CDATA[<p>Today I was asked how to transfer one report in the web module to a different user. The obvious reason for this is when someone leaves your company, the reports they had access to need to be transferred to the new person taking over their role. Unfortunately there’s not an easy way to do this via the user interface yet, but it is a planned feature.</p>
<p>In the mean time, you can do it by editing an XML file manually.<span id="more-988"></span></p>
<p>If you go to the Web Module’s data folder you will find a file called “Vantage Web Module.Reports”.  If you open this in Notepad, you’ll notice chunks of xml for each report:</p>
<p><code>&lt;WebReport&gt;<br />
&lt;Guid&gt;89208266-42e5-44bc-baa2-157c404c9688&lt;/Guid&gt;<br />
&lt;Title&gt;Business Unit Report&lt;/Title&gt;<br />
&lt;Date&gt;633945813293343143&lt;/Date&gt;<br />
&lt;Type&gt;Analysis&lt;/Type&gt;<br />
&lt;Access&gt;<br />
&lt;Everybody&gt;False&lt;/Everybody&gt;<br />
&lt;Attributed&gt;True&lt;/Attributed&gt;<br />
&lt;Specific&gt;True&lt;/Specific&gt;<br />
&lt;SpecificEntities&gt;<br />
&lt;item&gt;<span style="color: #ff0000;">person:CN=Luke,OU=Users,OU=Australia,OU=Webspy,DC=wsy,DC=com</span>&lt;/item&gt;<br />
&lt;/SpecificEntities&gt;<br />
&lt;Managers&gt;True&lt;/Managers&gt;<br />
&lt;ManagerLevelRestriction&gt;3&lt;/ManagerLevelRestriction&gt;<br />
&lt;/Access&gt;<br />
&lt;Attribution&gt;<span style="color: #ff0000;">person:CN=Scott,OU=Users,OU=Australia,OU=Webspy,DC=wsy,DC=com</span><br />
&lt;/Attribution&gt;<br />
&lt;/WebReport&gt;<br />
</code></p>
<p>Depending on how you published your reports, the unique ID of the person that currently has access to the reports will be mentioned in either the ‘SpecificEntities’ or ‘Attribution’ section.</p>
<p>You just need to find/replace this with the unique ID of the person you would like to transfer these reports to. You can find the unique ID of a person on the Organization screen in Vantage.  It’s called ‘Distinguished Name’:</p>
<div id="attachment_989" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/12/useridinvantage.png"><img class="size-medium wp-image-989" title="Finding a user's unique ID in Vantage" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/12/useridinvantage-300x210.png" alt="Finding a user's unique ID in Vantage" width="300" height="210" /></a><p class="wp-caption-text">Finding a user&#39;s unique ID in Vantage</p></div>
<p>A few more things:</p>
<ul>
<li> Make a backup of your original “Vantage Web Module.Reports” file before making any change.</li>
<li>As you can see above, people need to be entered into this XML file using the syntax <br /> &#8220;<strong>person:</strong><em>&lt;uniqueID&gt;</em>&#8220;</li>
<li> You will also need to stop IIS before making any change as the web module caches this data in its memory while running.</li>
</ul>
<p>As mentioned, creating a user interface to do this is a planned feature so <a title="Follow Us On Twitter" href="http://www.twitter.com/WebSpy" target="_blank">follow us on Twitter</a>, or <a title="Subscribe to our RSS feed" href="http://www.webspy.com.au/blogs/index.php/feed/" target="_blank">subscribe to our RSS feed</a> for updates!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-do-i-transfer-reports-to-a-different-user-in-the-web-module/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Taking the WebSpy out of the WebSpy Web Module</title>
		<link>http://www.webspy.com.au/blogs/index.php/taking-the-webspy-out-of-the-webspy-web-module/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/taking-the-webspy-out-of-the-webspy-web-module/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 09:09:13 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[branding]]></category>
		<category><![CDATA[Copying]]></category>
		<category><![CDATA[customize]]></category>
		<category><![CDATA[edit]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[images]]></category>
		<category><![CDATA[locations]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[logo]]></category>
		<category><![CDATA[paths]]></category>
		<category><![CDATA[rebrand]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[restyle]]></category>
		<category><![CDATA[style]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=930</guid>
		<description><![CDATA[One feature on our roadmap is the ability to re-brand the WebSpy Vantage Web Module, so that when your users hit the web module to view reports, they’re greeted with your own company logo and branding.

In the mean time, I thought I’d share a way to re-brand the main elements in the Web Module by editing a few files and replacing a few images.]]></description>
			<content:encoded><![CDATA[<p>One feature on our roadmap is the ability to re-brand the WebSpy Vantage Web Module, so that when your users hit the web module to view reports, they’re greeted with your own company logo and branding.</p>
<p>In the mean time, I thought I’d share a way to re-brand the main elements in the Web Module by editing a few files and replacing a few images.<span id="more-930"></span></p>
<p>The only issue with this technique is that any future auto-updates for the Web Module will overwrite your edited files, so you just need to keep a copy of your customized files, so that you can restore them again after the auto-update.</p>
<h2>Before you begin</h2>
<p>In order to edit anything, you first need to know where your Web Module is located on your web server’s hard drive. This can be found by opening IIS Manager (Start | Control Panel | Administrative Tools | Internet Information Services (IIS) Manager) expanding the left hand server/site tree to find your Web Module.</p>
<ul>
<li>In IIS7, select the Web Module and click Basic Settings… in the right hand ‘Actions’ panel. The location is specified in ‘Physical Path’.
<div id="attachment_959" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webmodulephysicalpath1.png"><img class="size-medium wp-image-959" title="Finding the Web Module's physical path in IIS7" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webmodulephysicalpath1-300x249.png" alt="Finding the Web Module's physical path in IIS7" width="300" height="249" /></a><p class="wp-caption-text">Finding the Web Module&#39;s physical path in IIS7</p></div></li>
<li>In IIS6, right-click the Web Module and select Properties… then go to the Home Directory tab. The location is specified in ‘Local Path’.</li>
</ul>
<p>Windows may also prevent you from editing these files directly due to permissions issues. I&#8217;ve found a good technique is to copy the files you want to edit to your desktop, edit them, and then copy them back into the Web Module&#8217;s physical path. Windows will then prompt you to elevate to administrator and the copy/replace will succeed.</p>
<h2>Ready To Go&#8230;</h2>
<p>There are a few places where the WebSpy logo and WebSpy Text is presented.</p>
<ul>
<li>The login page</li>
<li>The header bar</li>
<li>The welcome Page</li>
<li>Report cover pages</li>
</ul>
<h3>The Login page</h3>
<p>The logo displayed on the login page can be found at /images/logo.png. Replace this image with your own logo. Then open Default.aspx in the Web Module’s root folder in a text editor such as notepad, and replace the following line</p>
<p>&lt;img runat=&#8221;server&#8221; alt=&#8221;WebSpy&#8221; src=&#8221;~/Images/<strong>Get.ashx?image=Logo</strong>&#8221; /&gt;</p>
<p>with</p>
<p>&lt;img runat=&#8221;server&#8221; alt=&#8221;WebSpy&#8221; src=&#8221;~/Images/<strong>logo.png</strong>&#8221; /&gt;</p>
<h4>Before</h4>
<p><div id="attachment_962" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/loginscreen_before2.png"><img class="size-medium wp-image-962" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/loginscreen_before2-300x213.png" alt="Web Module's Login Page Before logo.png Change" width="300" height="213" /></a><p class="wp-caption-text">Web Module&#39;s Login Page Before logo.png Change</p></div>
<h4>After</h4>
<div id="attachment_963" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/loginscreen_after1.png"><img class="size-medium wp-image-963" title="Web Module Login Page After logo.png change" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/loginscreen_after1-300x213.png" alt="Web Module Login Page After logo.png change" width="300" height="213" /></a><p class="wp-caption-text">Web Module Login Page After logo.png change</p></div>
<h3>The header bar</h3>
<p>The header bar utilizes the image located a /Images/bauble.png. Replace this image with your own custom image.</p>
<p>Then open Navigation.Master  in the Web Module’s root folder in a text editor such as notepad, and replace the following line</p>
<div style="width: 620px;">
<p>&lt;div class=&#8221;headerBauble&#8221;&gt;&lt;img runat=&#8221;server&#8221; src=&#8221;~/Images/<strong>Get.ashx?image=Bauble</strong>&#8221; alt=&#8221;<strong>WebSpy</strong>&#8221; /&gt;&lt;/div&gt;</p>
<p>with</p>
<p>&lt;div class=&#8221;headerBauble&#8221;&gt;&lt;img runat=&#8221;server&#8221; src=&#8221;~/Images/<strong>bauble.png</strong>&#8221; alt=&#8221;<strong>Your Company Name</strong>&#8221; /&gt;&lt;/div&gt;</div>
<p>Also look for the text:</p>
<div style="width: 620px;">
<p>&lt;asp:Label ID=&#8221;Label1&#8243; runat=&#8221;server&#8221; Text=&#8221;<strong>res:Application.FullName</strong>&#8220;&gt;&lt;/asp:Label&gt;</p>
<p>and replace with</p>
<p>&lt;asp:Label ID=&#8221;Label1&#8243; runat=&#8221;server&#8221; Text=&#8221;<strong>Your Company Name</strong>&#8220;&gt;&lt;/asp:Label&gt;</div>
<h4>Before</h4>
<p style="text-align: center;">
<div id="attachment_965" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/headerbar_before1.png"><img class="size-medium wp-image-965 " title="Web Module's Header Bar Before Bauble.png and Text Changes" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/headerbar_before1-300x62.png" alt="Web Module's Header Bar After Bauble.png and Text Changes" width="300" height="62" /></a><p class="wp-caption-text">Web Module&#39;s Header Bar Before Bauble.png and Text Changes</p></div>
<h4>After</h4>
<div id="attachment_938" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/headerbar_after.png"><img class="size-medium wp-image-938" title="Web Module's Header Bar After Bauble.png and Text Change" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/headerbar_after-300x64.png" alt="Web Module's Header Bar After Bauble.png and Text Change" width="300" height="64" /></a><p class="wp-caption-text">Web Module&#39;s Header Bar After Bauble.png and Text Change</p></div>
<h3>The Welcome Page</h3>
<p>When you first login to the Web Module, you are presented with a Welcome Page. The first line on this page reads &#8220;Welcome to the WebSpy Vantage Web Module. You can change this by editing the first line in the Welcome.aspx file located in the Web Module&#8217;s root folder. Edit the section in bold below:<br />
&lt;%@ Page Language=&#8221;C#&#8221; MasterPageFile=&#8221;~/Navigation.Master&#8221; AutoEventWireup=&#8221;true&#8221; CodeBehind=&#8221;Welcome.aspx.cs&#8221; Inherits=&#8221;WebSpy.Vantage.WebModule.Welcome&#8221; Title=&#8221;<strong>Insert Custom Text Here</strong>&#8221; %&gt;</p>
<h4>Before</h4>
<div id="attachment_947" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/welcomepage_before.png"><img class="size-medium wp-image-947" title="Web Module's Welcome Page Before Text Change" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/welcomepage_before-300x155.png" alt="Web Module's Welcome Page Before Text Change" width="300" height="155" /></a><p class="wp-caption-text">Web Module&#39;s Welcome Page Before Text Change</p></div>
<h4>After</h4>
<div id="attachment_953" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/welcomepage_after1.png"><img class="size-medium wp-image-953" title="Web Module's Welcome Page After Text Change" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/welcomepage_after1-300x134.png" alt="Web Module's Welcome Page After Text Change" width="300" height="134" /></a><p class="wp-caption-text">Web Module&#39;s Welcome Page After Text Change</p></div>
<h3>The Report Cover Pages</h3>
<p>The Image used on the cover page of reports is much easier to change.</p>
<ol>
<li>Login to the Web Module as Administrator</li>
<li>Go to the Options Tab</li>
<li>Click ‘Report Logo’ under Web Module Options</li>
<li>Click Choose File, and select the image or logo you would like displayed on your report cover page</li>
<li>Click Upload</li>
</ol>
<h4>Before</h4>
<div id="attachment_940" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webmodulereport_before.png"><img class="size-medium wp-image-940" title="Web Module's Report Cover Page Before Report Logo Change" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webmodulereport_before-300x213.png" alt="Web Module's Report Cover Page Before Report Logo Change" width="300" height="213" /></a><p class="wp-caption-text">Web Module&#39;s Report Cover Page Before Report Logo Change</p></div>
<h4>After</h4>
<p><a href="../wp-content/uploads/2009/11/webmodulereport_after.png"></a></p>
<div id="attachment_941" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webmodulereport_after.png"><img class="size-medium wp-image-941" title="Web Module's Report Cover Page After Report Logo Change" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webmodulereport_after-300x213.png" alt="Web Module's Report Cover Page After Report Logo Change" width="300" height="213" /></a><p class="wp-caption-text">Web Module&#39;s Report Cover Page After Report Logo Change</p></div>
<h2>Summary</h2>
<p>The changes above cover a majority of the areas your users will come into contact with in the Web Module. There may be a few more instances of the word &#8220;WebSpy&#8221; but for the most part, it should just be a matter of opening the relevant .aspx file and editing the html.</p>
<p>As I mentioned, if you auto-update the Web Module (via the system tray icon on the Web Module server), your edited files will be overwritten. I recommend keeping a copy of your edited files in a safe place outside the Web Module&#8217;s physical folder, so that you can copy them back in after the update. If the only changes you make are the ones above, then you&#8217;ll need to keep a copy of:</p>
<ul>
<li>/Navigation.Master</li>
<li>/Default.aspx</li>
<li>/Welcome.aspx</li>
<li>/Images/logo.png</li>
<li>/Images/bauble.png</li>
</ul>
<p>We will also be adding the functionality to make these changes &#8216;properly&#8217; in a future build, so <a title="Follow Us On Twitter" href="http://www.twitter.com/WebSpy" target="_blank">follow us on Twitter</a>, or <a title="Subscribe to our RSS feed" href="http://www.webspy.com.au/blogs/index.php/feed/" target="_blank">subscribe to our RSS feed</a> for updates!</p>
<p>Cheers!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/taking-the-webspy-out-of-the-webspy-web-module/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lessons learned from a hacked Twitter account</title>
		<link>http://www.webspy.com.au/blogs/index.php/lessons-learned-from-a-hacked-twitter-account/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/lessons-learned-from-a-hacked-twitter-account/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 07:09:12 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Cyber Crime]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[direct message spam]]></category>
		<category><![CDATA[DM]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[tweets]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[URL shortening]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=878</guid>
		<description><![CDATA[If you follow @WebSpy on Twitter, you would have received a very strange Direct Message (DM) from us yesterday. Something along the lines of "rofl this you?" or "you're on this vid!" or "I found you on here!"

Unfortunately, the WebSpy Twitter account fell victim to a phishing scam, and as a result sent phishing spam to all our Twitter followers. We are embarrassed by the incident and we apologize to all of our followers, especially the ones that clicked the link in the DM and were caught by the phishing scam themselves.

Here's a rundown of the event in the hope that it will help others know what to look out for.]]></description>
			<content:encoded><![CDATA[<p>If you follow @WebSpy on Twitter, you would have received a very strange Direct Message (DM) from us yesterday. Something along the lines of &#8220;rofl this you?&#8221; or &#8220;you&#8217;re on this vid!&#8221; or &#8220;I found you on here!&#8221;</p>
<p>Unfortunately, the WebSpy Twitter account fell victim to a phishing scam, and as a result sent phishing spam to all our Twitter followers. We are embarrassed by the incident and we apologize to all of our followers, especially the ones that clicked the link in the DM and were caught by the phishing scam themselves.</p>
<p>Here&#8217;s a rundown of the event in the hope that it will help others know what to look out for.<span id="more-878"></span></p>
<h2>What Happened?</h2>
<p>The phishing scam works like this:</p>
<ol>
<li>You receive a strange yet intriguing Direct Message from someone you follow and likely trust. <strong>This is the key element to the scams success</strong>.</li>
<li>The DM contains a link using a shortened URL such as dwarfurl.com/blah. In our case, most of them were using dwarfurl.com, wapurl.co.uk, and 3.ly</li>
<li>You click the link and get taken to what appears to be the Twitter login page. But if you look at the URL it is actually something like blogs.videos.dsfasdc.com or  videos.twitter.dsfasdc.com. <strong>Checking the URL is the key to making sure the scam doesn&#8217;t get you too!</strong></li>
<li>You enter your Twitter login details. Reports of what happens after this login page vary. You may see the Twitter fail whale, or a blank page, or a random blog.</li>
<li>Now that the phishing site has your login details, the same Direct Messages is sent to all your Twitter contacts.</li>
<li>You eventually discover what happened. You feel like a violated idiot and start scrambling to fix everything.</li>
</ol>
<h2>What to do if it happens to you</h2>
<p>If the above sounds familiar, you need to login to Twitter right now and change your password to make sure the phishing site can no longer access your account. You also need to go to the Connections tab and disable any third party applications that look suspicious. You&#8217;ll then need to update the credentials in all the twitter clients, website/blog plug-ins, and anything else that may be using your old Twitter credentials.</p>
<p>Fortunately, we were still able to login to our Twitter account and change our password and disable third party connections. Thankfully there were not any new suspicious connections that we needed to worry about.</p>
<h2>Lessons Learned</h2>
<p>Now that we&#8217;ve fixed everything and regained control of our Twitter account, it&#8217;s good to sit back and reflect on what just happened and how to avoid it in the future.</p>
<p>You&#8217;ve probably heard all of this before. We had too. But it takes an incident like this to <em>really </em>think about and address any shortfalls in your own organization. Some of our followers were also caught out by the scam and these are people that are in the tech industry and generally know about these sorts of scams. We were definitely surprised that we fell for it!  So take a moment of your time to imagine your own Twitter account was compromised in the same way, then imagine all the possible ways it could have happened. Now go and take every precaution to ensure it doesn&#8217;t happen.</p>
<p>Having now been through it, here are some tips to help you avoid the same fate in the future.</p>
<ol>
<li>Just because a Direct Message comes from someone you trust, does not mean it is trustworthy. Always use caution!</li>
<li>Educate your employees &#8211; especially those that know your company&#8217;s Twitter credentials. The main goal you want to achieve here is getting your employees into the habit of glancing at the URL in the address bar of their browser before entering ANY login details. We used our own log analysis software (Vantage) to find out who ended up on the websites in question, and then spoke to them directly to ensure they understood what to look out for.</li>
<li>Use a Twitter application that can display the actual URL behind a shortened URL before clicking on the link. For TweetDeck users, go to Settings | General, and check &#8216;Show preview information for short URLs&#8217;. Please note, however that this function only works for a few specific URL shortening services.</li>
<li>If you&#8217;re using the Twitter web page directly, use a browser and plug-in that can expand shortened URLs such as Mozilla Firefox with <a href="https://addons.mozilla.org/en-US/firefox/addon/9549" target="_blank">Long URL Please</a>.</li>
<li>Use a browser with integrated anti-phishing security (such as Firefox or Google Chrome) and keep it up to date, or ensure you have good third party anti-phishing / anti-malware software installed.</li>
<li>As always, keep your security software and OS up to date.</li>
</ol>
<p>Our friends at Sophos also have some good information about the scam that you may like to read: <a title="Phish... it's what's for dinner" href="http://www.sophos.com/blogs/sophoslabs/?p=7366" target="_blank">http://www.sophos.com/blogs/sophoslabs/?p=7366</a></p>
<h2>Sorry!</h2>
<p>An event like this makes you realize how important Twitter is to the overall public perception of a company. Our followers trust us to deliver relevant and useful content about our key areas of expertise &#8211; log file analysis and reporting. We spend a large amount of effort researching and writing content to ensure our tweets provide our followers with a good source of information. Having a breach like this certainly degrades this public perception that we work so hard at trying to maintain.</p>
<p>I would therefore like to thank all our followers who have kept with us and not clicked the &#8216;Unfollow&#8217; button. Now that everything is under control again we will continue to bring you the best content we can provide about the log analysis and surrounding industries.</p>
<p>Once again, many many apologies to all of our followers, especially those that were affected.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/lessons-learned-from-a-hacked-twitter-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebSpy on Windows 7</title>
		<link>http://www.webspy.com.au/blogs/index.php/webspy-on-windows-7/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/webspy-on-windows-7/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 06:48:11 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[FlowMonitor]]></category>
		<category><![CDATA[Insight for Microsoft SBS Premium]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Sentinel]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Profiles]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[triggers]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=838</guid>
		<description><![CDATA[Now that Microsoft have officially released the long awaited Windows 7 Operating System, I thought I'd write a quick blog on WebSpy's current support for Windows 7.]]></description>
			<content:encoded><![CDATA[<p>Now that Microsoft have officially released the long awaited Windows 7 Operating System, I thought I&#8217;d write a quick blog on WebSpy&#8217;s current support for Windows 7.<span id="more-838"></span></p>
<h2>Supported on Windows 7</h2>
<p>The following WebSpy products support Windows 7:</p>
<ul>
<li><strong>WebSpy Analyzer</strong> (Standard, Premium and Giga)<br />
Analyzer customers will need to <a title="Download the latest version of Analyzer with support for Windows 7" href="http://www.webspy.com.au/community/software.aspx?productID=77,78,79" target="_blank">download</a> the latest version of their product as support for Windows 7 was uploaded today (9th November 2009).</li>
<li><strong>WebSpy Vantage </strong>(Premium, Giga and Ultimate)<br />
All products within the Vantage range have officially supported Windows 7 since version 2.2 was released on  24th June 2009.</li>
<li><strong>WebSpy Insight for Microsoft SBS Premium</strong><br />
Although Insight for Microsoft SBS Premium does not mention Windows 7 support in its documentation, it will install and run on Windows 7 without issue.</li>
</ul>
<h2>Not &#8216;Officially&#8217; Supported on Windows 7</h2>
<p>WebSpy Live, Sentinel and FlowMonitor are not yet officially supported on Windows 7 and will be updated soon. In the mean time, here are some instructions on how to get these products working on Windows 7 right now.</p>
<h3>WebSpy Live</h3>
<p>The existing version of Live will install and run on Windows 7 with one minor issue. When you run the application, there will be no Triggers, Aliases, or Profiles available.</p>
<p>To fix this:</p>
<ol>
<li>Install and run WebSpy Live on Windows 7.</li>
<li>Shutdown WebSpy Live by right-clicking the Live icon in the Windows system tray and selecting &#8216;Shutdown&#8217;
<p><div id="attachment_844" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/live-shutdown.png"><img class="size-medium wp-image-844" title="Shutting down WebSpy Live on Windows 7" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/live-shutdown-300x267.png" alt="Shutting down WebSpy Live on Windows 7" width="300" height="267" /></a><p class="wp-caption-text">Shutting down WebSpy Live on Windows 7</p></div></li>
<li>Download the following file containing WebSpy Live&#8217;s default Triggers, Aliases and Profiles:<br />
<a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/11/webspylivedefaultfiles.zip">WebSpy Live Default Files</a> (zip &#8211; 19.7 KB).</li>
<li>Extract the zip file to C:\Users\<strong>&lt;your user profile&gt;</strong>\AppData\Roaming\WebSpy\Live 2.2 and overwrite the existing files.</li>
<li>Run WebSpy Live. You will now be able to see a list of Triggers, Profiles and Aliases on the respective Configuration screens in WebSpy Live.</li>
</ol>
<h3>WebSpy Sentinel</h3>
<p>WebSpy Sentinel will not yet install on Windows 7 due to an issue with the included version of WinPCap (the packet driver used by Sentinel).</p>
<p>To fix this:</p>
<ol>
<li>Download and install the latest version (4.1.1) of WinPCap from <a title="Download WinPCap" href="http://www.winpcap.org/install/default.htm" target="_blank">http://www.winpcap.org/install/default.htm</a></li>
<li>Install WebSpy Sentinel. The product should install and run without issue.</li>
</ol>
<h3>FlowMonitor</h3>
<p>Unfortunately no work around is available for WebSpy FlowMonitor. We will update the product to work with Windows 7 as soon as possible.</p>
<h2>Got a problem?</h2>
<p>If you experience an issue running these products on Windows 7, or any other Windows operating system for that matter, please <a title="Contact WebSpy Support" href="http://www.webspy.com.au/support/contact.aspx" target="_blank">let us know!</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/webspy-on-windows-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Where does Vantage store data and how do I change it?</title>
		<link>http://www.webspy.com.au/blogs/index.php/where-does-vantage-store-data-and-how-do-i-change-it/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/where-does-vantage-store-data-and-how-do-i-change-it/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 08:05:02 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[disk space]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[locations]]></category>
		<category><![CDATA[paths]]></category>
		<category><![CDATA[Temp folder]]></category>
		<category><![CDATA[Vantage Web Data]]></category>
		<category><![CDATA[web.config]]></category>
		<category><![CDATA[WebSpy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=592</guid>
		<description><![CDATA[In the log file analysis world, we're always dealing with large volumes of data. By default, WebSpy Vantage stores its data, including the storages that you import log files into, somewhere on your c:\ drive. Changing this location to somewhere with more disk space is therefore one of the first steps that customers like to perform, so I thought I'd write a quick blog to explain the locations you should be aware of and how to change them.]]></description>
			<content:encoded><![CDATA[<p>In the log file analysis world, we&#8217;re always dealing with large volumes of data. By default, WebSpy Vantage stores its data, including the storages that you import log files into, somewhere on your c:\ drive. Changing this location to somewhere with more disk space is therefore one of the first steps that customers like to perform, so I thought I&#8217;d write a quick blog to explain the locations you should be aware of and how to change them.<span id="more-592"></span></p>
<h2>Vantage&#8217;s Storage Location</h2>
<p>If you&#8217;re using <strong>Vantage Premium or Giga</strong>, there&#8217;s only one location you need to be aware of. That is where Vantage keeps its storages (Vantage&#8217;s custom database that log files are imported into). This setting is easily changed by going to <strong>Tools | Options | Paths</strong> and double clicking the Storages path. Easy.</p>
<h2>Web Module Storage Locations</h2>
<p>If you&#8217;re using <strong>Vantage Ultimate</strong>, you also need to be aware of the Storage location mentioned above, but you also may need to adjust where the Web Module stores its data.  There are two locations you need to be aware of here:</p>
<ol>
<li> <strong>The Web Module Data Location</strong><br />
This is where the Web Module permanently keeps it’s storages, reports and settings</li>
<li> <strong>The Windows temporary folder </strong><br />
This is where Vantage keeps storages while they’re being processed before uploading them to the Web Module’s data location</li>
</ol>
<h3>The Web Module Data Location</h3>
<p>The <strong>data location for the Web Module</strong> is specified during installation and defaults to <em>C:\Vantage Web Data</em>. If you have already installed the Web Module, you can change this location using the following steps:</p>
<ol>
<li> Find the Web Module’s Web.Config file. The Web.Config file can be found in the Web Module’s physical folder. If you don’t know where the Web Module’s physical folder is:
<ol>
<li>Open Microsoft IIS (Control Panel | Administrative Tools |  Internet Information Services (IIS) Manager)</li>
<li>Select the Web Module in the left hand side (e.g. Server-&gt; Sites -&gt;Default Web Site -&gt; webmodule).
<ul>
<li><strong>If you’re using IIS 6</strong>, Right-click the Web Module site and select <strong>Properties </strong>then go to the Home Directory tab to find the physical folder.</li>
<li><strong>If you’re using II7</strong>, select your Web Module site and click <strong>Basic Settings&#8230; </strong></li>
</ul>
</ol>
<li> Open the Web.Config file in Notepad.</li>
<li> Find the line that looks like this:
<pre>&lt;add key="SettingsPath" value="C:\Vantage Web Data"/&gt;</pre>
</li>
<li>Change <strong>c:\Vantage Web Data</strong> to the location you would like to use and save the file.</li>
<li>In Windows Explorer, copy all files and folders from C:\Vantage Web Data (or where ever your original location was) to the new location you specified in step 4</li>
<li>Restart IIS by going to <strong>Start | Run</strong> and type <strong>iisreset /restart</strong></li>
</ol>
<h3>The Windows Temporary Folder</h3>
<p><strong>The Windows Temporary folder</strong> can also be modified, but please note this is a system wide change.</p>
<ol>
<li> Right-click ‘My computer’ and select Properties.</li>
<li> Go to Advanced and Click the Environment Variables button</li>
<li> Change the location for the &#8216;TEMP&#8217; and &#8216;TMP&#8217; environment variables (do not use the same location specified in step 4 above)</li>
</ol>
<p>Vantage and the Vantage Web Module (Ultimate only) will now use your new locations to temporarily and permanently keep your Storage files.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/where-does-vantage-store-data-and-how-do-i-change-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Forefront TMG Release Candidate now available</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-release-candidate-now-available/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-release-candidate-now-available/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 01:00:34 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[release candidate]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=734</guid>
		<description><![CDATA[Microsoft have announced the availability of Microsoft Forefront Threat Management Gateway (TMG) Release Candidate (RC).  This is the final public release of TMG before it is made available to purchase. 

If you're considering upgrading your ISA Server to TMG, this means that you can start your deployment using the Release Candidate, and simply switch it to a licenced version with no additional configuration changes once the full release is available.]]></description>
			<content:encoded><![CDATA[<p>Microsoft has announced the availability of Microsoft Forefront Threat Management Gateway (TMG) Release Candidate (RC).  This is the final public release of TMG before it is made available to purchase. </p>
<p>If you&#8217;re considering upgrading your ISA Server to TMG, this means that you can start your deployment using the Release Candidate, and simply switch it to a licensed version with no additional configuration changes once the full release is available.<span id="more-734"></span> At least, that is what Vladimir Holostov (Lead Program Manager, Release Manager for Forefront TMG 2010) states on the Forefront TMG (ISA Server) Product Team Blog:</p>
<blockquote><p>&#8220;The final product will be released later this year and you can expect it to behave exactly like the Release Candidate. You can install Forefront TMG 2010 RC today and upgrade to a licensed version once available without changing the configuration of your deployment.&#8221; </p></blockquote>
<p>To offer some peace of mind for organizations considering the deployment, Vladimir also mentions that &#8220;Forefront TMG 2010 RC is deployed at three major Microsoft sites located around the world in Haifa, Bellevue and Redmond. More than 20,000 employees are already protected by TMG and these deployments have already accumulated more than 5,000 hours of runtime, performing extremely well under heavy load&#8221;.</p>
<p>No major features have been added to the Release Candidate since Beta 3, however there have been improvements geared around tightening up security, reliability and performance and telemetry. For more information about the release candidate, please visit the<br />
<a href="http://blogs.technet.com/isablog/archive/2009/10/11/forefront-threat-management-gateway-2010-release-candidate-now-available.aspx" target="_blank">Forefront TMG (ISA Server) Product Team Blog</a>. </p>
<p>You can also download the release candidate <a href="http://www.microsoft.com/DOWNLOADS/details.aspx?FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd&#038;displaylang=en" target="_blank">here</a></p>
<p>I mentioned in my last blog posting that WebSpy has introduced support for reporting on Microsoft Forefront TMG log formats in the Vantage product range. To try it out, please make sure you have installed Vantage 2.2 (any flavour &#8211; Premium, Giga or Ultimate), and then select <strong>Tools | Check for updates </strong>to download build 2.2.0.10 or above.  You can then import your TMG log files by selecting the Microsoft FTMG loader in the import wizard.<br />
<div id="attachment_596" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg.png"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg-300x225.png" alt="Importing Microsoft Forefront Threat Management Gateway Log Files" title="Importing Microsoft Forefront Threat Management Gateway Log Files" width="300" height="225" class="size-medium wp-image-596" /></a><p class="wp-caption-text">Importing Microsoft Forefront Threat Management Gateway Log Files</p></div></p>
<p>We&#8217;re very interested to hear your thoughts on the reporting functionality, so please go ahead and give it a go!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-release-candidate-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exciting New Features in Vantage Update 2.2.0.10</title>
		<link>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 07:27:29 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Bug Fixes]]></category>
		<category><![CDATA[CSV]]></category>
		<category><![CDATA[Data Purge]]></category>
		<category><![CDATA[ExoServer]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Import Organization]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[New Features]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Tasks]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=593</guid>
		<description><![CDATA[Attention all Vantage customers (and triallers). We've just released build 2.2.0.8 as an auto-update. This build includes new features such as scheduled data purge, support for Microsoft Forefront Threat Management Gateway, and scheduling CSV imports into your Organizational structure.]]></description>
			<content:encoded><![CDATA[<p>Attention all Vantage customers (and evaluators). We&#8217;ve just released build 2.2.0.10 as an auto-update. This build includes support for Microsoft Forefront Threat Management Gateway, and new features such as scheduled &#8216;data purge&#8217; and scheduling CSV imports into your Organizational structure.</p>
<p><span id="more-593"></span></p>
<p>You should be prompted to update your software on startup, but if you&#8217;ve turned off that feature, simply go to <strong>Tools | Check for Updates</strong>.</p>
<h2>New Features</h2>
<p>This new build sports the following new features:</p>
<ul>
<li> <strong>Support for Microsoft Forefront Threat Management Gateway (Beta)</strong><br />Microsoft Forefront Threat Management Gateway (FTMG) is still currently in Beta, and is due to be released around November 2009. For those that do not know, FTMG is the next version of Microsoft&#8217;s popular ISA Server. Information and downloads for FTMG can be found here <a href="http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/tmg-beta.aspx">http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/tmg-beta.aspx</a>. We have added support for FTMG beta 2 and 3 for both the W3C text logs (recommended) and the internal SQL Server Express Database logs. If you are currently trialling FTMG, we are very interested to hear your feedback. Let us know how you go!
<div id="attachment_596" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg.png"><img class="size-medium wp-image-596 " title="Now Supported - Microsoft Forefront Threat Management Gateway" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg-300x225.png" alt="Microsoft Forefront Threat Management Gateway" width="300" height="225" /></a><p class="wp-caption-text">Now Supported - Microsoft Forefront Threat Management Gateway</p></div></li>
<li><span style="background-color: #ffffff;"><strong>Data purge</strong><br />
You can now purge data from a storage, and schedule this purge to occur on a regular basis using Tasks. Purge options include data between a date range, data before a date, data after a date, data older than a date relative to now, and all data. This feature will let you easily maintain a single storage that only includes data for the last month or day.</p>
<p><div id="attachment_594" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/purge-storage.png"><img class="size-medium wp-image-594" title="Purge Storage Wizard" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/purge-storage-300x225.png" alt="Options for Purging data from your storage" width="300" height="225" /></a><p class="wp-caption-text">Options for Purging data from your storage</p></div>
<p></span></li>
<li><strong>Import Organization from CSV can now be scheduled using Tasks</strong><br />
<span style="font-weight: normal;"><span style="background-color: #ffffff;">If you are importing your organizational structure from CSV, you can now schedule this action using Tasks. This enables you to update your organizational structure before any reports are run.</span></span></p>
<p><div id="attachment_597" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-from-csv.png"><img class="size-medium wp-image-597" title="Import Organization from CSV via Tasks" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-from-csv-300x224.png" alt="Import Organization from CSV via Tasks" width="300" height="224" /></a><p class="wp-caption-text">Import Organization from CSV via Tasks</p></div></li>
<li> <strong><span style="background-color: #ffffff;">Added Support for ExoServer Web</span></strong><br />
If you&#8217;re running ExoServer Web, you can now analyze it&#8217;s logs using WebSpy Vantage.</li>
</ul>
<h2>Fixes</h2>
<p>We also fixed some things that may have been bugging you:</p>
<ul>
<li><span style="background-color: #ffffff;">Improved the start time for the application by improving the logic to check for Storage damage.</span></li>
<li><span style="background-color: #ffffff;">Fixed the IronPort loader (Fixed out of range issues on excessive size fields).</span></li>
<li><span style="background-color: #ffffff;">&#8220;Having&#8221; filters no longer override the sort order of a Report Template node.</span></li>
<li><span style="background-color: #ffffff;">Fixed an issue that may result in duplicated storages after migrating settings from earlier versions.</span></li>
<li><span style="background-color: #ffffff;">Fixed the inability to remove invalid entities from web module permissions list (users that no longer exist).</span></li>
<li>Fixed a timeout issue when publishing storages to the web module.</li>
</ul>
<p>Why are you still reading? Go update now!</p>
<p>Have fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remove Username-Password Prompts from the Web Module with Windows Authentication</title>
		<link>http://www.webspy.com.au/blogs/index.php/remove-username-password-prompts-from-the-web-module-with-windows-authentication/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/remove-username-password-prompts-from-the-web-module-with-windows-authentication/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 05:31:01 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[anonymous authentication]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[usernames]]></category>
		<category><![CDATA[Vantage Ultimate]]></category>
		<category><![CDATA[Windows Authentication]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=569</guid>
		<description><![CDATA[A great feature of Vantage Ultimate is its ability to publish reports and storages to the Web Module so that users can login, view their reports, and analyze data. But no one wants to have to remember yet another username and password combination to login to the Web Module, so make it easy on your users by using Windows Authentication. This way, as long as a user is logged into their Windows machine with their Windows domain username, they will sail straight into the Web Module without being prompted for a username or password.]]></description>
			<content:encoded><![CDATA[<p>A great feature of Vantage Ultimate is its ability to publish reports and storages to the Web Module so that users can login, view their reports and analyze data. But no one wants to have to remember yet another username and password combination to login to the Web Module, so make it easy on your users by using Windows Authentication. This way, as long as a user is logged into their Windows machine with their Windows domain username, they will sail straight into the Web Module without being prompted for a username or password.<span id="more-569"></span></p>
<p><span style="background-color: #ffffff;">To use Windows Authentication, there are just a few things you need to do.</span></p>
<ol>
<li>Set the Web Module&#8217;s Authentication type to <strong>IIS Integrated, <span style="font-weight: normal;">and a</span><span style="background-color: #ffffff; "><span style="font-weight: normal;">dd</span></span><span style="background-color: #ffffff; font-weight: normal; "> your administrators in the form of <strong>domain\username</strong></span></strong></li>
<li>Enable Windows Authentication and disable Anonymous authentication in IIS.</li>
<li>Ensure all users in your Organization screen have a login name in the form of <strong>domain\username</strong>. Use the &#8216;Prefix&#8217; option to prefix &#8220;domain\&#8221; (without the quotes) to your usernames names when importing your Organization from LDAP or LDIF.</li>
<li><span style="background-color: #ffffff;">Connect Vantage and the Web Module using the new authentication details and synchronize your Organization. </span></li>
</ol>
<h3>1. Set the Web Module&#8217;s Authentication type to IIS Integrated, and add your Administrators.</h3>
<p><span style="background-color: #ffffff;">When you first install the Web Module, the first screen you see is the &#8216;Initial Configuration Wizard&#8217; that guides you through the process of selecting your authentication type and specifying your administrator(s). If you have already been through this Wizard and are currently using Vantage In-Built or Client Certificate authentication, you can easily reset this initial configuration wizard. Simply login to the Web Module with your current administrator details and go to <strong>Options | Maintenance | Reset Initial Configuration Wizard.</strong> </span></p>
<blockquote><p>Note: You can also change your authentication and administrator options individually using the Authentication and Administrator options on the Options tab of the Web Module.  However, for ease of demonstration, I&#8217;ll use the Initial Configuration Wizard method.</p></blockquote>
<p>Now that you&#8217;re at the Initial Configuration Wizard, proceed through the wizard, selecting IIS Integrated authentication and entering your administrators in the form of domain\username (replace domain with your organization&#8217;s AD domain, and username with the sAMAccountName of your administrator.</p>
<div id="attachment_574" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-welcome-page.png"><img class="size-medium wp-image-574" title="initial-configuration-wizard-welcome-page" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-welcome-page-300x240.png" alt="Initial Configuration Wizard - Welcome Page" width="300" height="240" /></a><p class="wp-caption-text">Initial Configuration Wizard - Welcome Page</p></div>
<div id="attachment_571" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-authentication-page.png"><img class="size-medium wp-image-571" title="initial-configuration-wizard-authentication-page" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-authentication-page-300x236.png" alt="Initial Configuration Wizard - Authentication Page" width="300" height="236" /></a><p class="wp-caption-text">Initial Configuration Wizard - Authentication Page</p></div>
<div id="attachment_572" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-delegate-administrators-page.png"><img class="size-medium wp-image-572" title="initial-configuration-wizard-delegate-administrators-page" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-delegate-administrators-page-300x237.png" alt="Initial Configuration Wizard - Delegate Administrators Page" width="300" height="237" /></a><p class="wp-caption-text">Initial Configuration Wizard - Delegate Administrators Page</p></div>
<div id="attachment_573" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-summary-page.png"><img class="size-medium wp-image-573" title="initial-configuration-wizard-summary-page" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/initial-configuration-wizard-summary-page-300x237.png" alt="Initial Configuration Wizard - Summary Page" width="300" height="237" /></a><p class="wp-caption-text">Initial Configuration Wizard - Summary Page</p></div>
<p>Click <strong>Finish</strong>, and if the authentication was successfully changed, you should get a message saying &#8216;The specified credentials were not accepted&#8221;.</p>
<div id="attachment_576" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/the-specified-credentials-were-not-accepted.png"><img class="size-medium wp-image-576" title="the-specified-credentials-were-not-accepted" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/the-specified-credentials-were-not-accepted-300x142.png" alt="The 'Specified credentials were not accepted' message." width="300" height="142" /></a><p class="wp-caption-text">The &#39;Specified credentials were not accepted&#39; message.</p></div>
<p>Don&#8217;t panic at this point. This message is an indication that the authentication was successfully changed and that the Web Module is now listening for IIS to pass through Windows Usernames. The reason you&#8217;re getting this message is because IIS is not yet passing through Windows Usernames to the Web Module. This is configured in the next step.</p>
<h3>2. Enable Windows Authentication and disable Anonymous authentication in IIS.</h3>
<p>Now that the Web Module is expecting IIS to authenticate your users, you need to set up  IIS  to do this.</p>
<ol>
<li><span style="background-color: #ffffff;">Open IIS by navigating to <strong>Start | Control Panel | Administrative Tools </strong>and double-clicking on <strong>Internet Information Services (IIS) Manager</strong>.</span></li>
<li><span style="background-color: #ffffff;">Navigate to the Web Module site or virtual directory in the left hand &#8216;Connections&#8217; Panel. It will be located under &lt;Server Name&gt;\&lt;Sites&gt;. For example, MyServer-&gt;Sites-&gt;Default Web Site-&gt;webmodule.</span></li>
</ol>
<ul>
<li><span style="background-color: #ffffff;">If you&#8217;re running<strong> IIS7</strong> ( Windows Server 2008, Vista or Windows 7)</span>
<ol>
<li><span style="background-color: #ffffff; ">Select the Web Module site and ensure the &#8216;Features&#8217; tab is selected at the bottom of the middle pane.</span></li>
<li><span style="background-color: #ffffff; ">Double-click the &#8216;Authentication&#8217; feature.</span></li>
<li><span style="background-color: #ffffff; ">Right-click &#8216;Anonymous Authentication&#8217; and select <strong>Disable</strong></span></li>
<li><span style="background-color: #ffffff; "><strong><span style="background-color: #ffffff; font-weight: normal; ">Right-click and &#8216;Windows Authentication&#8217; and select <strong>Enable</strong></span></strong></span></li>
<li><span style="background-color: #ffffff; "><strong><span style="background-color: #ffffff; font-weight: normal; "><strong><span style="background-color: #ffffff; font-weight: normal; ">Restart IIS by selecting your server in the right hand connections pane, and clicking <strong>Restart</strong> in the &#8216;Actions&#8217; pane on the right.</span></strong></span></strong></span></li>
</ol>
</li>
</ul>
<ul>
<li><span style="font-weight: normal;">If you&#8217;re running </span>IIS6 or 5.1<span style="font-weight: normal;"> (Windows Server 2003, Windows XP)</span>
<ol>
<li><span style="background-color: #ffffff;">Right-click Web Module site and select Properties.</span></li>
<li><span style="background-color: #ffffff;">Go to the Directory Security tab</span></li>
<li><span style="background-color: #ffffff;">Under &#8216;Authentication and access control&#8217; click the <strong>Edit</strong> button.</span></li>
<li><span style="background-color: #ffffff;">Uncheck &#8216;Enable anonymous access&#8217; and check &#8216;Integrated Windows authentication&#8217;</span></li>
<li><span style="background-color: #ffffff;">Restart IIS by right-clicking the local server, select All Tasks, and then click <strong>Restart IIS</strong>.</span></li>
</ol>
</li>
</ul>
<p>If you added your own Windows login name as an administrator in step 1, you can now test the authentication is working. Go back to the Web Module in your browser and click <strong>Refresh</strong>. You will be presented with an &#8216;Authentication Required&#8217; dialog where you can enter your username and password.</p>
<div id="attachment_577" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/authentication-required.png"><img class="size-medium wp-image-577" title="Authentication Required Dialog" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/authentication-required-300x181.png" alt="Authentication Required Dialog" width="300" height="181" /></a><p class="wp-caption-text">Authentication Required Dialog</p></div>
<p>Again, ensure your username is in the form of domain\username. Click <strong>OK</strong>, and you should log straight into the Web Module using Windows Authentication.</p>
<h3>3. Ensure all users in your Organization screen have a login name in the form of domain\username</h3>
<p>Now your administrator account can log into the Web Module using Windows Authentication, but all other users will not be able to log in unless they have their login name specified in the form of domain\username. This is done in Vantage Ultimate on the Organization screen.</p>
<div id="attachment_578" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/organization-screen-showing-correct-login-name.png"><img class="size-medium wp-image-578" title="organization-screen-showing-correct-login-name" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/organization-screen-showing-correct-login-name-300x213.png" alt="Organization Screen showing correct login name for Windows Authentication" width="300" height="213" /></a><p class="wp-caption-text">Organization Screen showing correct login name for Windows Authentication</p></div>
<p>If you&#8217;re importing your users from LDAP or LDIF, make sure you use the &#8216;Prefix&#8217; option on the User Details page to prefix domain\ before your imported usernames. For example:</p>
<p><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-with-prefix-option.png"><img class="aligncenter size-medium wp-image-579" title="import-organization-with-prefix-option" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-with-prefix-option-300x225.png" alt="import-organization-with-prefix-option" width="300" height="225" /></a></p>
<h3>4. Connect Vantage and the Web Module using the new authentication details, and synchronize your Organization.</h3>
<p>In order to publish information to the Web Module, you need to add a connection between Vantage and the Web Module. This is done on the Web Module screen in Vantage Ultimate.</p>
<ol>
<li><span style="background-color: #ffffff;">Click <strong>Add Web Module</strong> (or if you already had a web module before changing the authentication details, select it and click <strong>Properties</strong>)</span></li>
<li><span style="background-color: #ffffff;">Enter the server &amp; virtual directory of the Web module, and enter the correct credentials ensuring domain is specified.</span></li>
<li><span style="background-color: #ffffff;">Click OK to connect.</span></li>
</ol>
<div id="attachment_580" class="wp-caption aligncenter" style="width: 306px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/connect-to-web-module.png"><img class="size-medium wp-image-580" title="connect-to-web-module" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/connect-to-web-module-296x300.png" alt="Connect to Web Module dialog" width="296" height="300" /></a><p class="wp-caption-text">Connect to Web Module dialog</p></div>
<p><span style="background-color: #ffffff;">Once connected, synchronize Vantage with the Web Module by clicking the <strong>Synchronize </strong>link in the Web Module task pad. You may also want to provide permissions for your users in the Permissions section on the Web Module screen.</span></p>
<p>That&#8217;s it. You can now test that everything is working by getting one of your users to access the Web Module&#8217;s URL. They should sail straight in with no username/password prompt.</p>
<p>I hope this helps! Please let me know your feedback by emailing me, or leaving a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/remove-username-password-prompts-from-the-web-module-with-windows-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Increase importing speed by utilizing dates in log file names</title>
		<link>http://www.webspy.com.au/blogs/index.php/increase-importing-speed-by-utilizing-dates-in-log-file-names/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/increase-importing-speed-by-utilizing-dates-in-log-file-names/#comments</comments>
		<pubDate>Fri, 14 Aug 2009 06:21:10 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[date formats]]></category>
		<category><![CDATA[Date Modifiers]]></category>
		<category><![CDATA[File Masks]]></category>
		<category><![CDATA[Filtering]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Speed]]></category>
		<category><![CDATA[Tasks]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=467</guid>
		<description><![CDATA[Using Date Modifiers in file masks are a great way to increase the speed of your imports as they remove all the logs you don’t care about from the import list.

If you're using WebSpy Vantage, you are probably interested in filtering your log file imports by date (only import files from the month of June for example). The obvious way to do this is to specify a date filter using the filters page in the Input Wizard. The problem is Vantage will still check every record in every log file being imported to see if it matches the date filter. If you have months or years worth of logs in the folder being imported, that's a lot of data that Vantage has to pointlessly sift through.

The good news is, if your log files contain the date in their file name, then you can use file masks to instruct Vantage to never touch these unwanted files.]]></description>
			<content:encoded><![CDATA[<p>Using Date Modifiers in file masks are a great way to increase the speed of your imports as they remove all the logs you don’t care about from the import list.</p>
<p>If you&#8217;re using WebSpy Vantage, you are probably interested in filtering your log file imports by date (only import files from the month of June for example). The obvious way to do this is to specify a date filter using the filters page in the Input Wizard. The problem is Vantage will still check every record in every log file being imported to see if it matches the date filter. If you have months or years worth of logs in the folder being imported, that&#8217;s a lot of data that Vantage has to pointlessly sift through.</p>
<p>The good news is, if your log files contain the date in their file name, then you can use file masks to instruct Vantage to never touch these unwanted files.</p>
<p><span id="more-467"></span></p>
<h2>A bit about file masks&#8230;</h2>
<p>You can specify file masks such as *, *.log, *.gzip, *WEB*.w3c, etc to import logs with specific file extensions, or with specific strings in the file name (such as WEB or FWS to import only Microsoft ISA Web Proxy or Firewall logs respectively).</p>
<p>But if your log file contains the date in the file name, you can also use date modifiers in the file mask to select logs from a particular month, date or year.</p>
<p>Say you have log files that look like this:</p>
<ul>
<li>
<pre>20090801.log</pre>
</li>
<li>
<pre>20090802.log</pre>
</li>
<li>
<pre>20090803.log</pre>
</li>
</ul>
<p>and so on..</p>
<p>You can create a simple file mask to only import log files from the month of August very easily using 200908*, or 200908*.log.</p>
<h2>Using date modifiers in file masks</h2>
<p>But if you&#8217;re using Tasks to automatically create a new storage each month, you don&#8217;t want to have to worry about manually changing the file mask to 200909*.log when the first day of the next month rolls around.</p>
<p>So intsead, you can use a date modifier in the file mask that will automatically select the logs for the current month, every time your task runs. For the above example, the file mask looks like this:</p>
<ul>
<li>
<pre>%[yyyyMM]* (you can also use %[yyyyMM]*.log)</pre>
</li>
</ul>
<p>When the task runs, %[yyyyMM] will be replaced with actual values from the current date. So if the task runs on the 1st of August 2009, the file mask will become 200909* (or 200909*.log).</p>
<h3>Dealing with different date formats</h3>
<p>You can also use date modifiers for log files that look like this:</p>
<ul>
<li>
<pre>2009-Aug-01.log</pre>
</li>
<li>
<pre>2009-Aug-02.log</pre>
</li>
<li>
<pre>2009-Aug-03.log</pre>
</li>
</ul>
<p>In this case the file mask looks like:</p>
<ul>
<li>
<pre>%[yyyy-MMM]* - notice the three MMM's as opposed to two MM's used previously.</pre>
</li>
</ul>
<p>Vantage uses the custom date and time format strings available in the .NET framework, so for more information on whether to use m or M or MMM, please refer to this article <a title=".NET Custom Date and Time Format Strings" href="http://msdn.microsoft.com/en-us/library/8kb3ddd4.aspx" target="_blank">http://msdn.microsoft.com/en-us/library/8kb3ddd4.aspx</a></p>
<h3>Importing logs from previous months</h3>
<p>If you would like to import logs from a previous month, this can also be done by adding an additional element to the date modifier. For example, to import the previous months logs you can use:</p>
<ul>
<li>
<pre>%[-1m,yyyyMM]*</pre>
</li>
</ul>
<p>Notice the -1m meaning &#8216;minus one month&#8217;. You can also use -1d (for minus one day), or -1y (for minus one year).</p>
<h3>More examples</h3>
<p>Here are some more examples to give you an idea of what is possible using date modifiers.  Assuming the date is 14th of August 2009:</p>
<ul>
<li>
<pre><strong>%[-1y,yyyyMM]*.log</strong> will create a file mask of 200808*.log</pre>
</li>
<li>
<pre><strong>%[yyyy-MM-dd]*.log</strong> will create a file mask of 2009-08-14*.log</pre>
</li>
<li>
<pre><strong>%[-4d,yyyyMMdd]*.log</strong> will create a file mask of 20090810*.log</pre>
</li>
<li>
<pre><strong>%[1-m,-4d,yyyyMMdd]*.log</strong> will create a file mask of 20090710*.log</pre>
</li>
<li>
<pre><strong>%[-1y,1-m,-4d,yyyyMMdd]*.log</strong> will create a file mask of 20080710*.log</pre>
</li>
<li>
<pre><strong>ISALOG_%[-1m,yyyyMM]*_WEB_*.w3c </strong>will create a file mask of  ISALOG_200907*_WEB_*.w3c</pre>
</li>
<li>
<pre><strong>*%[-1m,yyyyMM]* </strong>will create a file mask of  *200907*</pre>
</li>
</ul>
<h3>Adding a file mask</h3>
<p>File masks are configured on the Input Selection page of the Input Wizard, when you select <strong>Add | Folder</strong>.</p>
<div id="attachment_468" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/08/filemask.png"><img class="size-medium wp-image-468" title="Adding a File Mask" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/08/filemask-300x246.png" alt="Adding a File Mask" width="300" height="246" /></a><p class="wp-caption-text">Adding a File Mask</p></div>
<p>There is also an option to save the literal date into the file mask when the task is run.  For more information on this option, please see <a title="Using Date Modifiers in File Masks - New Features " href="http://www.webspy.com.au/blogs/index.php/13/" target="_blank">my previous blog about this feature</a>.</p>
<h2>Other uses for date modifiers</h2>
<p>Date Modifiers are a great way to speed up log file imports, but you can also use them when specifying storage names as well as report names. For example, if you specify a storage name of %[yyyyMM]_storage, this will create storages with the names 200907_storage, 200908_storage and so on. When selecting the storages to report on, you can click the <strong>Add </strong>button on the storage selection toolbar in the Report Wizard, and specify storages such as %[-1m,yyyyMM]_storage, to report on the previous month&#8217;s storage.  For more information, please see <a title="Automatic Importing and Reporting using Tasks" href="http://www.webspy.com.au/support/knowledgebase/viewKBArticle.aspx?id=146" target="_blank">Automatic Importing and Reporting using Tasks.</a></p>
<p>I hope this helps someone out there. Let me know how you go!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/increase-importing-speed-by-utilizing-dates-in-log-file-names/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Video: Setup a complete Internet monitoring solution in less than 15 minutes!</title>
		<link>http://www.webspy.com.au/blogs/index.php/setup-a-complete-internet-monitoring-solution-in-less-than-15-minutes/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/setup-a-complete-internet-monitoring-solution-in-less-than-15-minutes/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 07:59:31 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Sentinel]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[alerts]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[data capture]]></category>
		<category><![CDATA[demonstration]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=445</guid>
		<description><![CDATA[Here's a video I put together demonstrating how to get up and running with a complete monitoring and reporting solution in less than 15 minutes. The video demonstrates three products: WebSpy Sentinel, for complete data capture, WebSpy Live for real time alerts, and WebSpy Analyzer Standard for analysis and reporting.]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a video I put together demonstrating how to get up and running with a complete monitoring and reporting solution in less than 15 minutes. The video demonstrates three products: <a href="http://www.webspy.com.au/products/addons/sentinel/default.aspx">WebSpy Sentinel</a>, for complete data capture, <a href="http://www.webspy.com.au/products/addons/live/default.aspx">WebSpy Live</a> for real time alerts, and <a href="http://www.webspy.com.au/analyzerstandard/default.aspx">WebSpy Analyzer Standard</a> for analysis and reporting.</p>
<p>We&#8217;ve got a <a href="http://www.webspy.com.au/analyzerstandard/offer.aspx">great deal</a> at the moment where you get 20% off Live and Sentinel if you purchase them online with Analyzer Standard.</p>
<p><object width="400" height="255" data="http://blip.tv/scripts/flash/showplayer.swf?enablejs=true&amp;file=http%3A//blip.tv/rss/flash/2481372&amp;feedurl=http%3A//webspy.blip.tv/rss/&amp;autostart=false&amp;brandname=WebSpy&amp;brandlink=http%3A//webspy.blip.tv/" type="application/x-shockwave-flash"><param name="id" value="showplayer" /><param name="allowfullscreen" value="true" /><param name="quality" value="best" /><param name="src" value="http://blip.tv/scripts/flash/showplayer.swf?enablejs=true&amp;file=http%3A//blip.tv/rss/flash/2481372&amp;feedurl=http%3A//webspy.blip.tv/rss/&amp;autostart=false&amp;brandname=WebSpy&amp;brandlink=http%3A//webspy.blip.tv/" /></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/setup-a-complete-internet-monitoring-solution-in-less-than-15-minutes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Convert Microsoft ISA 2006 MSDE logs to WebSpy compatible text logs</title>
		<link>http://www.webspy.com.au/blogs/index.php/convert-microsoft-isa-2006-msde-logs-to-webspy-compatible-text-logs/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/convert-microsoft-isa-2006-msde-logs-to-webspy-compatible-text-logs/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 04:23:25 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Firewall Logs]]></category>
		<category><![CDATA[ISA 2006]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[log conversion]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[MSDE]]></category>
		<category><![CDATA[MSDE To Text]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Web Proxy Logs]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=394</guid>
		<description><![CDATA[A few customers have experienced some issues converting their ISA MSDE logs to text format using Microsofts MSDEToText.vbs script for ISA 2006. We've therefore created a modified version of the script that creates compatible log files for WebSpy software.]]></description>
			<content:encoded><![CDATA[<p>Some customers have experienced issues converting their ISA MSDE logs to text using Microsoft’s MSDEToText.vbs script for ISA 2006 (available at <a href="http://www.microsoft.com/downloads/details.aspx?familyid=23531736-942f-466c-acb3-861a899d37b4&#038;displaylang=en">http://www.microsoft.com/downloads/details.aspx?familyid=23531736-942f-466c-acb3-861a899d37b4&#038;displaylang=en</a>)</p>
<p>If you convert your logs to text using this script, they won&#8217;t import into WebSpy Vantage or Analyzer due to an extra line break in the header of the file (after #fields:). </p>
<p>We&#8217;ve therefore created a modified version of the script that creates compatible log files for WebSpy software. </p>
<p><strong>Download the modified MSDEToText script:<br />
<a href="http://www.webspy.com/resources/utils/MSDEToText.zip">MSDEToText.zip -26 KB</a></strong></p>
<p>Also make sure the file names of your output log files contain the word WEB (for Web Proxy logs) or FWS (for Firewall Logs) as Analyzer and Vantage use these strings to automatically detect the type of ISA log file.</p>
<p>Happy converting!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/convert-microsoft-isa-2006-msde-logs-to-webspy-compatible-text-logs/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Video: How To Remove Clutter From Your Web Reports</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-to-remove-clutter-from-your-web-reports/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-to-remove-clutter-from-your-web-reports/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 09:10:02 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[ad servers]]></category>
		<category><![CDATA[camtasia studio]]></category>
		<category><![CDATA[clean reports]]></category>
		<category><![CDATA[demonstration]]></category>
		<category><![CDATA[Filtering]]></category>
		<category><![CDATA[Noise]]></category>
		<category><![CDATA[Remove Clutter]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[sub-domains]]></category>
		<category><![CDATA[top sites]]></category>
		<category><![CDATA[tracking servers]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[web sites]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=430</guid>
		<description><![CDATA[I was conducting a demonstration the other day on how to use a few tricks in WebSpy Vantage to filter out noise and clutter from web reports. If you have ever looked through the raw list of web sites visited by people in your organization, I'm sure you know what I mean. 

Watching a single video on YouTube will probably generate a list of about three to five sites such as lax-v41.lax.youtube.com, www.youtube.com, img.youtube.com, and so on. Your list of top sites also probably contains hits to ad servers and tracking servers, such as doubleclick.net, google-analytics.com and imrworldwide.com. All this clutter gets in the way of determining what sites were 'intentionally' visited.]]></description>
			<content:encoded><![CDATA[<p>I was conducting a demonstration the other day on how to use a few tricks in WebSpy Vantage to filter out noise and clutter from web reports. If you have ever looked through the raw list of web sites visited by people in your organization, I&#8217;m sure you know what I mean.</p>
<p>Watching a single video on YouTube will probably generate a list of about three to five sites such as lax-v41.lax.youtube.com, www.youtube.com, img.youtube.com, and so on. Your list of top sites also probably contains hits to ad servers and tracking servers, such as doubleclick.net, google-analytics.com and imrworldwide.com. All this clutter gets in the way of determining what sites were &#8216;intentionally&#8217; visited. <span id="more-430"></span></p>
<p>Fortunately there are a few simple steps you can take to exclude this information from your reports. Watching is much easier than reading, so I thought I&#8217;d create a video demo to walk you through the process.</p>
<p><object width="425" height="344" data="http://www.youtube.com/v/RzT_6pj6SCc&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/RzT_6pj6SCc&amp;hl=en&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /></object></p>
<p>By the way, this is the first video demo of what I hope will be many more to come. I created it using <a href="http://www.techsmith.com/camtasia.asp">TechSmith&#8217;s Camtasia Studio</a> which is by far the best screen recording software I&#8217;ve used. All the zooming you see throughout the demonstration is completely auto-magical! It&#8217;s a brilliant piece of software that has saved me hours of time. Props to the guys at TechSmith! The one pitfall of Camtasia is that it seems to make me sound like a geek with a raw Aussie accent&#8230; I hope they fix that in the next version.</p>
<p>Anyway, I hope you find this useful.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-to-remove-clutter-from-your-web-reports/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage 2.2 now available!</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-22-now-available/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-22-now-available/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 03:55:14 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Multi-processing]]></category>
		<category><![CDATA[Multi-threading]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Profiles]]></category>
		<category><![CDATA[Report Style]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Storage Repair]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=331</guid>
		<description><![CDATA[I'm happy to announce the release of Vantage 2.2! All three products in the Vantage range (Premium, Giga and Ultimate) have been update with the following features:
Multi-processing, Improved report styles, Updated Aliases and Profiles, Storage Repair Utility, Save / Open Tasks.

Obviously, the multi-processing feature is the big one! Many of you (Vantage customers) have been running Vantage on multi-core or multi-cpu machines and just dying for Vantage to grab hold of the CPUs and make them work. You should be happy with this new build. ]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m happy to announce the release of Vantage 2.2! <a href="http://www.webspy.com.au/products/vantage/default.aspx#range">Download Vantage 2.2 here.</a></p>
<p>All three products in the Vantage range (Premium, Giga and Ultimate) have been updated with the following features:<span id="more-331"></span></p>
<ul>
<li><strong>Multi-processing</strong><br />
Vantage now utilizes the extra processing power on machines with multiple cores or CPUs to import log files and generate reports faster.<br />
<div id="attachment_122" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/vantage_performancetab.jpg"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/vantage_performancetab-300x211.jpg" alt="The new Performance tab in Vantage" title="vantage_performancetab" width="300" height="211" class="size-medium wp-image-122" /></a><p class="wp-caption-text">The new Performance tab in Vantage</p></div>
</li>
<li><strong>Improved report styles</strong><br />
HTML (including MHT) reports are now sporting an updated look and feel.<br />
<div id="attachment_334" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/newreportstyle.png"><img class="size-medium wp-image-334" title="New Report Style" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/newreportstyle-300x224.png" alt="New Report Style" width="300" height="224" /></a><p class="wp-caption-text">New Report Style</p></div></li>
<li><strong>Updated Aliases and Profiles</strong><br />Added support for the latest search engines, social networking sites, operating systems and user agents.<br />
<div id="attachment_343" class="wp-caption aligncenter" style="width: 305px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/searchosbrowsercollage.png"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/searchosbrowsercollage.png" alt="Profiles Aliases support the latest Internet tools and technolgies." title="Search OS Browser Collage" width="295" height="162" class="size-full wp-image-343" /></a><p class="wp-caption-text">Profiles Aliases support the latest Internet tools and technologies.</p></div></p>
</li>
<li><strong>Storage Repair Utility</strong><br />
Storages can become damaged if there is a system crash or if WebSpy.Vantage.exe process is ended when an import is in progress. Damaged storages are now detected automatically and you have the option of repairing them. Storages can also be manually checked and repaired on the Storage properties dialog.<br />
<div id="attachment_345" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/storage-diagnostic1.png"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/storage-diagnostic1-300x296.png" alt="Storage Repair Utility" title="Storage Repair Utility" width="300" height="296" class="size-medium wp-image-345" /></a><p class="wp-caption-text">Storage Repair Utility</p></div>
</li>
<li><strong>Save / Open Tasks</strong><br />Scheduled Tasks can now be saved to an external file (.Tasks) for backup and migration purposes.<br />
<div id="attachment_346" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/saveopentasks.png"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/06/saveopentasks-300x243.png" alt="Save and Open Tasks" title="Save and Open Tasks" width="300" height="243" class="size-medium wp-image-346" /></a><p class="wp-caption-text">Save and Open Tasks</p></div>
</li>
</ul>
<p>Obviously, the multi-processing feature is the big one! Many of you (Vantage customers) have been running Vantage on multi-core or multi-cpu machines and just dying for Vantage to grab hold of the CPUs and make them work. You should be happy with this new build. Import a folder full of log files and watch 6 to 8 logs import simultaneously instead of watching them import one after the other. Run a full analysis or a comprehensive report with no filters and watch your CPU jump into gear to generate the report in 30% &#8211; 50% of the time. We&#8217;re expecting this to be a very popular update, especially among our larger customers.</p>
<p>Multi-processing is a great new feature, but be aware that there are some circumstances where Vantage will not be able to utilise more CPU power when generating reports. For example, if your report contains filters that significantly cuts down the amount of data in your storage that needs analysis, Vantage&#8217;s analysis engine and your CPUs will not be significantly pushed. Also see <a href="http://www.webspy.com.au/blogs/index.php/vantage-now-with-multi-processing/">my earlier blog</a> for more information on how the report structure can also affect the performance.</p>
<p>To get hold of this build, simply <a href="http://www.webspy.com.au/products/vantage/default.aspx#range">download the latest version of Vantage</a> from our website. It will run side by side with your existing Vantage 2.1 installation, which minimizes any downtime, and makes it easy to transfer all your settings across (use the Migration Wizard in the Tools menu). Then you can uninstall Vantage 2.1 when you&#8217;re ready.</p>
<p>Let us know how you go by leaving comments below, or by <a href="http://www.twitter.com/webspy">tweeting us</a>.</p>
<p>Cheers!<br />
Scott</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-22-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forefront Threat Management Gateway Beta 3 Now available</title>
		<link>http://www.webspy.com.au/blogs/index.php/forefront-threat-management-gateway-beta-3-now-available/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/forefront-threat-management-gateway-beta-3-now-available/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 03:49:18 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Beta 3]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Repuation Services]]></category>
		<category><![CDATA[MRS]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Threat Management Gateway Reporting]]></category>
		<category><![CDATA[URL Filtering]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=295</guid>
		<description><![CDATA[A couple of weeks ago I <a href="http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/">posted a blog</a> regarding Microsoft's upcoming Beta 3 release of Forefront Threat Management Gateway (TMG) which will be replacing Microsoft ISA server. Well, it's now been released and can be downloaded from the Microsoft Download Center.]]></description>
			<content:encoded><![CDATA[<p>A couple of weeks ago I <a href="http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/">posted a blog</a> regarding Microsoft&#8217;s upcoming Beta 3 release of Forefront Threat Management Gateway (TMG) which will be replacing Microsoft ISA server.</p>
<p>Well, it&#8217;s now been released and can be downloaded from the Microsoft Download Center:<span id="more-295"></span><br />
<a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&#038;FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd">http://www.microsoft.com/downloads/details.aspx?displaylang=en&#038;FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd</a></p>
<p>One of the major improvements in Beta 3 is URL filtering which leverages Microsoft Reputation Services (MRS). With regards to this, Microsoft says:</p>
<blockquote><p>&#8220;At the time of this release, the MRS database content is being populated and updated continuously as part of the initial beta service offering. As this process continues, URL filtering categorization accuracy and comprehensiveness will increase. A telemetry package designed for improving the quality of URL filtering database and collecting your feedback is planned to be released soon. Please check back for updates in August.&#8221;</p></blockquote>
<p>Support for importing Microsoft TMG log files into your favorite WebSpy product is coming soon so stay tuned! Subscribe to the <a href="http://www.webspy.com.au/blogs/index.php/feed/">WebSpy blog RSS feed</a> or <a href="http://www.twitter.com/WebSpy">follow us on twitter</a> if you want to be notified as soon as it&#8217;s available.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/forefront-threat-management-gateway-beta-3-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft to announce Beta 3 for Threat Management Gateway (the new ISA Server)</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/#comments</comments>
		<pubDate>Mon, 18 May 2009 15:51:32 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Beta 3]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[Intrusion Prevention]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Network Inspection System]]></category>
		<category><![CDATA[NIS]]></category>
		<category><![CDATA[SQL Express Log Files]]></category>
		<category><![CDATA[Threat Management Gateway Reporting]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[TMG Log Files]]></category>
		<category><![CDATA[TMG Reprting]]></category>
		<category><![CDATA[URL Filtering]]></category>
		<category><![CDATA[W3C Log Files]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=201</guid>
		<description><![CDATA[It sounds like Threat Management Gateway (TMG), the new re-branded version of ISA Server, has been a popular topic at this years TechEd event in the US. 

According to the <a href="http://blogs.technet.com/isablog/archive/2009/05/16/teched-2009-post-show-feedback.aspx">latest blog from TMG's Product Unit Manager</a>, David B. Cross, Beta 3 will be released in the next couple of weeks. As for the full release, David says that they are still on track for Q4 this calendar year. ]]></description>
			<content:encoded><![CDATA[<p>It sounds like Threat Management Gateway (TMG), the new re-branded version of ISA Server, has been a popular topic at this years TechEd event in the US. </p>
<p>According to the <a href="http://blogs.technet.com/isablog/archive/2009/05/16/teched-2009-post-show-feedback.aspx">latest blog from TMG&#8217;s Product Unit Manager</a>, David B. Cross, Beta 3 will be released in the next couple of weeks. As for the full release, David says that they are still on track for Q4 this calendar year. <span id="more-201"></span></p>
<p>Beta 3 will introduce URL filtering that is &#8216;fully integrated&#8217; with TMG&#8217;s web policy rules, and also utilizes Microsoft Reputation Services. </p>
<p>Microsoft are also introducing Intrusion Prevention and Detection (IPS/IDS) capabilities in TMG. These systems will utilize a technology they&#8217;re calling Network Inspection System (NIS) that detects attacks using signatures of known vulnerabilities, downloaded from the Microsoft Malware Protection Center. For more information on NIS see <a href="http://blogs.technet.com/isablog/archive/2009/04/12/exercising-nis-with-test-signature.aspx">http://blogs.technet.com/isablog/archive/2009/04/12/exercising-nis-with-test-signature.aspx</a></p>
<p>If you&#8217;re currently using ISA 2004 or 2006, upgrading to TMG will consist of exporting rules and settings from ISA, then importing them into a clean installation of TMG. TMG will also only run on Windows Server 2008.</p>
<p>Improving the on-box reporting has not been a focus for the TMG development team, so analyzing TMG’s web proxy and firewall logs is still the best way to go for in depth reporting. </p>
<p>If you’re interested in reporting on your TMG log files stay tuned! We’re currently implementing support for the SQL Express, W3C and Native text logs. WebSpy Vantage is likely to be the first application to include the feature, with Analyzer and Live soon to follow. </p>
<p>All going well, you can expect to see TMG support in your favourite WebSpy app within the next month or so. If you want to be notified once we’ve added support, just leave a comment below.</p>
<p>Cheers!<br />
Scott.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-to-announce-beta-3-for-threat-management-gateway-the-new-isa-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Migrating WebSpy Vantage to a different machine</title>
		<link>http://www.webspy.com.au/blogs/index.php/migrating-webspy-vantage-onto-a-different-machine/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/migrating-webspy-vantage-onto-a-different-machine/#comments</comments>
		<pubDate>Thu, 14 May 2009 15:39:45 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Configuration]]></category>
		<category><![CDATA[Copying]]></category>
		<category><![CDATA[Migrating]]></category>
		<category><![CDATA[Moving]]></category>
		<category><![CDATA[Settings]]></category>
		<category><![CDATA[Upgrading]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=184</guid>
		<description><![CDATA[Imagine you've just spent the last six months setting up storages, aliases, profiles, scheduled tasks and so on, and you need to migrate all this to another machine. Of course you could go to the Aliases screen and click 'Save Aliases', then go to the new machine and click 'Open Aliases', and repeat for every setting you want to move across. But there is an easier way.]]></description>
			<content:encoded><![CDATA[<p>Imagine you&#8217;ve just spent the last six months setting up storages, aliases, profiles, scheduled tasks and so on, and you need to migrate all this to another machine. Of course you could go to the Aliases screen and click &#8216;Save Aliases&#8217;, then go to the new machine and click &#8216;Open Aliases&#8217;, and repeat for every setting you want to move across. But there is an easier way.<br />
<span id="more-184"></span><br />
When Vantage closes, it saves all its current configuration to files located in the following locations:</p>
<ul>
<li><strong>Windows Vista &amp; Server 2008:</strong><br />
C:\Users\&lt;user profile&gt;\AppData\Roaming\WebSpy\Vantage &lt;edition&gt; &lt;version&gt;</li>
<li><strong>Windows XP &amp; Server 2003:</strong><br />
C:\Documents and Settings\&lt;user profile&gt;\Application Data\WebSpy\Vantage &lt;edition&gt; &lt;version&gt;</li>
</ul>
<p>When Vantage opens, it loads the information contained in these files.</p>
<p>To move all your settings across, you can simply copy all the files in this location on your original machine, into the same folder on the new machine (make sure Vantage is closed when you do this).</p>
<p>When you open Vantage on the new machine and you&#8217;ll have all your settings moved across.</p>
<p>If you&#8217;re using scheduled tasks, one thing to note is that copying these files will not recreate the Windows scheduled task jobs. To get your tasks functioning on the new machine:</p>
<ul>
<li>Go to the <strong>Tasks </strong>tab and double-click each scheduled task.</li>
<li>Proceed through the wizard and make sure all the settings are correct.</li>
<li>Enter your authentication details on the last page and click <strong>OK</strong>.</li>
</ul>
<p>This will create a new Windows scheduled task job which should run as it did on the old machine.</p>
<p>Please note that this process only moves &#8217;settings&#8217; across to the new machine. If Storages and Reports were being written to a location on the old machine, then you will need to move these across to the Storages and Reports locations on the new machine (check <strong>Tools | Options | Paths</strong> for these locations).</p>
<p>Also take access privileges into account. If you&#8217;re old installation was set to create storages in \\server\mystorages, make sure the new machine also has write privileges to this location.</p>
<p>That&#8217;s pretty much all there is too it. Happy migrating!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/migrating-webspy-vantage-onto-a-different-machine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage now with multi-processing!</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-now-with-multi-processing/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-now-with-multi-processing/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 05:41:40 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Multi-processing]]></category>
		<category><![CDATA[Multi-threading]]></category>
		<category><![CDATA[Performance]]></category>
		<category><![CDATA[Speed]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=118</guid>
		<description><![CDATA[We've been doing some work of late to make Vantage take advantage of multi-cpu and multi-core processors. It looks like we've improved the performance of importing more than one log file by around 50%, and the most common reporting scenarios by around 30%.  Before we release this build into the wild, I'd like to give it as much field testing as possible. If you are interested in obtaining a copy of this build...


]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve been doing some work lately to make Vantage take advantage of multi-cpu and multi-core processors. It looks like we&#8217;ve improved the performance of importing multiple log files by around 50%, and the most common reporting scenarios by around 30% (tested on a quad-core CPU).  Before we release this build into the wild, I&#8217;d like to give it as much field testing as possible. If you are interested in obtaining a copy of this build, <span id="more-118"></span>please contact me using the comments form below, or email me at scottg at webspy dot com.</p>
<p>The multi-processing build features a new tab called &#8216;Performance&#8217; in <strong>Tools | Options</strong>. Ensure ‘Use multi-processing’ is checked, and set the &#8216;Maximum Concurrent Threads&#8217; value to twice the number of logical/physical CPUs you have. For example, set it to 4 on a dual core, 8 on a quad-core, or 16 on a machine with two quad-core CPUs. Feel free to also play around with this value, but we have found this formula to be optimal and we&#8217;ll automatically set this as default in future builds.</p>
<div id="attachment_122" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/vantage_performancetab.jpg"><img class="size-medium wp-image-122" title="vantage_performancetab" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/vantage_performancetab-300x211.jpg" alt="The new Performance tab in Vantage" width="300" height="211" /></a><p class="wp-caption-text">The new Performance tab in Vantage</p></div>
<p>You’ll notice that if you import a folder of logs, about 6-8 logs will import simultaneously. Simply importing one log file will not show any speed improvement.</p>
<p>Multi-processing will only benefit report generation if your report template contains side-by-side summaries as opposed to drilldown summaries. Here&#8217;s what I mean by a template with side-by-side summaries:</p>
<div id="attachment_119" class="wp-caption aligncenter" style="width: 258px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/side-by-side-summaries.jpg"><img class="size-full wp-image-119" title="side-by-side-summaries" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/side-by-side-summaries.jpg" alt="A report template that only has side-by-side summaries" width="248" height="218" /></a><p class="wp-caption-text">A report template that only has side-by-side summaries</p></div>
<p>And here&#8217;s what I mean by a template with drilldown summaries</p>
<div id="attachment_121" class="wp-caption aligncenter" style="width: 230px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/drilldown-summaries.jpg"><img class="size-full wp-image-121" title="A report template with only drilldown summaries" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/drilldown-summaries.jpg" alt="A report template with only drilldown summaries" width="220" height="70" /></a><p class="wp-caption-text">A report template with only drilldown summaries</p></div>
<p>Basically, each side-by-side summary will get processed simultaneously, but any drilldowns will be processed sequentially.</p>
<p>Most report templates consist of both side-by-side AND drilldown summaries, such as:</p>
<div id="attachment_120" class="wp-caption aligncenter" style="width: 189px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/side-by-side-and-drilldown-summaries.jpg"><img class="size-medium wp-image-120" title="side-by-side-and-drilldown-summaries" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/04/side-by-side-and-drilldown-summaries-179x300.jpg" alt="A report template with both side-by-side and drilldown summaries" width="179" height="300" /></a><p class="wp-caption-text">A report template with both side-by-side and drilldown summaries</p></div>
<p>The amount that these templates benefit from multi-processing will depend on the number of side-by-side summaries.</p>
<p>If this sounds like something you&#8217;d like to try, please contact me for a copy of the build!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-now-with-multi-processing/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Updates to Vantage, Analyzer &amp; Live</title>
		<link>http://www.webspy.com.au/blogs/index.php/updates-to-vantage-analyzer-live/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/updates-to-vantage-analyzer-live/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 05:55:58 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=105</guid>
		<description><![CDATA[We’ve issued a bunch of auto updates for nearly all WebSpy products today

 

Of particular note is a fix to the Vantage range:

·         Fix: Improved partition matching when filtering by a date range

 

This will benefit you if you're running reports with a date range filter such as last week or yesterday (which is pretty much everyone), and are using the default storage partitioning scheme of "Date" (again... pretty much everyone). ]]></description>
			<content:encoded><![CDATA[<p>We’ve issued a bunch of auto updates for nearly all WebSpy products today</p>
<p>Of particular note is a fix to the Vantage range:</p>
<ul>
<li>Fix: Improved partition matching when filtering by a date range</li>
</ul>
<p>This will benefit you if you&#8217;re running reports with a date range filter such as last week or yesterday (which is pretty much everyone), and are using the default storage partitioning scheme of &#8220;Date&#8221; (again&#8230; pretty much everyone).<span id="more-105"></span></p>
<p>There was an issue in Vantage’s partition filtering technology which meant that if you specified a date range filter, Vantage would still analyse an entire storage, instead of just the date partitions you selected in the filter.</p>
<p>So do a <strong>Tools | Check for updates</strong> to grab build 2.1.2.12 and you should see a significant speed improvement in report generation. Woo hoo!</p>
<p>Here&#8217;s more details on the changes:</p>
<h3>VANTAGE</h3>
<p><strong>Application Changes</strong></p>
<ul>
<li>New: Added support for importing event logs from non-domain machines.</li>
<li>New: Added the ability for the Troubleshoot Alias/Profiles to export results to a file.</li>
<li>New: Added hash salt and substring functions to the expression language.</li>
<li>New: Added support for computing a date-modified file mask at import time and storing it back into the storage.</li>
<li>New: Added a file mask override to the Import new hits to existing storage task action.</li>
<li>New (Vantage Ulitmate &amp; Giga): Added support for attributes on Organization groups.</li>
<li>New (Vantage Ultimate): Added custom expression-based split in Web Module publishing (Beta).</li>
<li>New (Vantage Ultimate): Changed the publish report wizard to allow selection of multiple storages.</li>
<li>Fix: Improved partition matching when filtering by a date range.</li>
<li>Fix: Fixed an issue with registrations and trial extensions.</li>
<li>Fix: Fixed zero-width rectangle exceptions in chart renderer.</li>
<li>Fix: Fixed overflow exceptions on footer generation in report tables.</li>
<li>Fix: Fixed XmlException error during settings load.</li>
<li>Fix: Storage now clears previous data when it is overwritten when using the ‘Import logs into new storage’ task.</li>
<li>Fix (Vantage Ultimate &amp; Giga): Fixed issues with date range selection when collating reports.</li>
<li>Fix (Vantage Ultimate): Web Module dock no longer checks for updates to a web module server when ‘Check for updates on startup’ is disabled.</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>New: Added Phion Firewall</li>
<li>New: Added Watchguard Firebox X Core</li>
<li>New: Added NetScreen 208</li>
<li>New: Added IPCop</li>
<li>New: Added Astaro Mail Gateway</li>
<li>New: Added iPrism Monitor v4.2</li>
<li>New: Added Cisco VPN Concentrator</li>
<li>New: Added Snare for Lotus Notes</li>
<li>Improved: Added string host name to Kerio Mail Server</li>
<li>Improved: Improved support for NetIntact PacketLogic</li>
<li>Fix: Made changes to the IronPort detection method to fix the issue when importing via FTP.</li>
<li>Fixed: Fixed date format issue in event log import. You can now import event logs in any regional configuration.</li>
<li>Fix: Postfix loader no longer drops session state after the first recipient line</li>
<li>Fix: Updated the detection method in CheckPoint Firewall-1 Syslog format.</li>
<li>Fix: Fixed an issue in iSheriff where a drilldown on the Category field would display no results.</li>
<li>Fix: Various fixes to Netscreen 10</li>
<li>Fix: Various fixes to Arkoon PxLog</li>
<li>Fix: Vaious fixes to Sendmail MTA</li>
</ul>
<h3>VANTAGE WEB MODULE</h3>
<ul>
<li>FIX: When sorting by key column the chart will now use the &#8220;hits&#8221; aggregate for value (prevents the chart from going wacky)</li>
</ul>
<h3>ANALYZER</h3>
<p><strong>Application Changes</strong></p>
<ul>
<li>NEW: Added support for manual configuration of ISA block list settings (Tools | Options | Block Lists)</li>
<li>Fix: Fixed an issue with registrations and trial extensions</li>
<li>Fix: Fixed report wizard configuration to restore the sort column from the report template</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>New: Added Webroot</li>
<li>New: Added Qmail Desknow Mail Server</li>
<li>New: Added UserGate Proxy Server 2.7</li>
<li>New: Added Netgear FVX538</li>
<li>Improved: Added support for importing allowed/blocked status in Sophos Web format</li>
<li>Fixed: Changed CC Proxy field count check</li>
<li>Fixed: Changed ISA SQL loaders to use size delta fields instead of cumulative fields</li>
<li>Fixed: Modified Exchange 2000/2003 loader to discard message cache after import</li>
</ul>
<h3>LIVE</h3>
<p><strong>Application changes</strong></p>
<ul>
<li>Fix: Fixed an issue with registrations and trial extensions</li>
</ul>
<p><strong>Loader changes:</strong></p>
<ul>
<li>New: Added Webroot</li>
<li>New: Added Qmail Desknow Mail Server</li>
<li>New: Added UserGate Proxy Server 2.7</li>
<li>New: Added Netgear FVX538</li>
<li>Improved: Added support for importing allowed/blocked status in Sophos Web format</li>
<li>Fixed: Changed CC Proxy field count check</li>
<li>Fixed: Modified Exchange 2000/2003 loader to discard message cache after import</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/updates-to-vantage-analyzer-live/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disabling time synchronization between guest and host in Microsoft Virtual PC</title>
		<link>http://www.webspy.com.au/blogs/index.php/disabling-time-synchronization-between-guest-and-host-in-microsoft-virtual-pc/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/disabling-time-synchronization-between-guest-and-host-in-microsoft-virtual-pc/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 07:29:02 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Time Synchronization]]></category>
		<category><![CDATA[Virtual PC]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=87</guid>
		<description><![CDATA[Microsoft Virtual PC synchronizes the time between the guest and host operating systems. This is great until you have the need to set the clock forward or backwards in your VM, as it snaps back to the current time after about 5 seconds. I went hunting through the options in the Virtual PC UI but didn't find anything related to disabling this option. A bit of googling later and I've got it disabled by adding a few lines of XML to the .vmc file.]]></description>
			<content:encoded><![CDATA[<p>Microsoft Virtual PC synchronizes the time between the guest and host operating systems. This is great until you have the need to set the clock forward or backwards in your VM, as it snaps back to the current time after about 5 seconds.</p>
<p>I went hunting through the options in the Virtual PC UI but didn&#8217;t find anything related to disabling this option. A bit of googling later and I&#8217;ve got it disabled by adding a few lines of XML to the .vmc file.<span id="more-87"></span></p>
<p>First, make sure your VM is shut down and Virtual PC is closed.</p>
<p>Then find your .vmc file and open it in a text editor such as Notepad.  By default, Virtual PC creates .vmc files in My Documents\My Virtual Machines.</p>
<p>Find the <code>&lt;/microsoft&gt;</code> tag and insert the following lines directly above it:</p>
<p><code>&lt;components&gt;<br />
&lt;host_time_sync&gt;<br />
&lt;enabled type="boolean"&gt;false&lt;/enabled&gt;<br />
&lt;/host_time_sync&gt;<br />
&lt;/components&gt;</code></p>
<p>For example:</p>
<div id="attachment_90" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/virtualpchosttimesynchoption.jpg"><img class="size-medium wp-image-90" title="Disabling the host time synchoption option in a .vmc file" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/virtualpchosttimesynchoption-300x215.jpg" alt="Disabling the host time synchoption option in a .vmc file" width="300" height="215" /></a><p class="wp-caption-text">Disabling the host time synchoption option in a .vmc file</p></div>
<p>Then Open Virtual PC, start your VM and you&#8217;re all done!</p>
<p>This was tested on Windows Vista 6.0.6001, SP1 using Microsoft Virtual PC 2007 (6.0.156.0)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/disabling-time-synchronization-between-guest-and-host-in-microsoft-virtual-pc/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Enhancement to the Sophos Loader in Analyzer</title>
		<link>http://www.webspy.com.au/blogs/index.php/enhancement-to-the-sophos-loader-in-analyzer/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/enhancement-to-the-sophos-loader-in-analyzer/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 01:42:42 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Blocked]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Not Blocked]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Web Security Appliance]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=71</guid>
		<description><![CDATA[We’ve made a modification to Analyzer’s Sophos loader so that it takes the value from the action field to determine blocked/allowed.

The fix can be applied to WebSpy Analyzer Giga 2.3, Analyzer Premium 4.3 or Analyzer Standard 4.3]]></description>
			<content:encoded><![CDATA[<p>We’ve made a modification to Analyzer’s Sophos Web Security Appliance loader so that it takes the value from the action field to determine blocked/allowed.</p>
<p>The fix can be applied to WebSpy Analyzer Giga 2.3, Analyzer Premium 4.3 or Analyzer Standard 4.3. <span id="more-71"></span>If you&#8217;re not running the latest version, <a href="http://www.webspy.com/products/analyzer/download.aspx">download it now!</a></p>
<p>You can download the new loader build that we created today at either of these locations:<br />
<a href="ftp://ftp.webspy.com/webspy/Builds/Loader4.3.2.6.zip">USA West Coast (FTP)</a><br />
<a href="ftp://ftpwest.webspy.com/webspy/Builds/Loader4.3.2.6.zip">USA East Coast (FTP)</a></p>
<p>Then extract the zip file into Analyzer&#8217;s installation folder (usually C:\Program Files\WebSpy\Analyzer <em>flavour</em> 4.3\) and overwrite the existing file.</p>
<p>Then go to the storages screen and select your Sophos storage(s) and click ‘Reload all hits’. This will re-import your log files using the modified loader and will populated the ‘Blocked’ summary appropriately.  To check it out, go to the Summaries screen and run a Full Analysis. Then go to the &#8216;Blocked&#8217; summary and you should see two items &#8211; &#8216;Blocked&#8217; and &#8216;Not Blocked&#8217;. Drilldown into whichever one you care about to analyze the sites, users, files, browsing times, size downloaded etc. Go nuts!</p>
<p>You can also filter out blocked hits (or Not Blocked hits) from your reports. On the Reports Screen, click Generate a new report and go through the report wizard with this filter (this example shows filtering out blocked hits).</p>
<div id="attachment_72" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-custom_filters.jpg"><img class="size-medium wp-image-72" title="Analyzer Report Wizard - Select Custom Filters" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-custom_filters-300x230.jpg" alt="Analyzer Report Wizard - Select Custom Filters" width="300" height="230" /></a><p class="wp-caption-text">Analyzer Report Wizard - Select Custom Filters</p></div>
<div id="attachment_73" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_filter.jpg"><img class="size-medium wp-image-73" title="Analyzer Report Wizard - Selecting the 'Blocked' Summary as a Filter" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_filter-300x230.jpg" alt="Analyzer Report Wizard - Selecting the 'Blocked' Summary as a Filter" width="300" height="230" /></a><p class="wp-caption-text">Analyzer Report Wizard - Selecting the &#39;Blocked&#39; Summary as a Filter</p></div>
<div id="attachment_74" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard_add_blocked.jpg"><img class="size-medium wp-image-74" title="Analyzer Report Wizard - Adding the items that you want to filter" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard_add_blocked-300x232.jpg" alt="Analyzer Report Wizard - Adding the items that you want to filter" width="300" height="232" /></a><p class="wp-caption-text">Analyzer Report Wizard - Adding the items that you want to filter</p></div>
<div id="attachment_75" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_criteria.jpg"><img class="size-medium wp-image-75" title="Analyzer Report Wizard - final filter to exclude 'Blocked' hits" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_criteria-300x230.jpg" alt="Analyzer Report Wizard - final filter to exclude 'Blocked' hits" width="300" height="230" /></a><p class="wp-caption-text">Analyzer Report Wizard - final filter to exclude &#39;Blocked&#39; hits</p></div>
<p>Then proceed through the report wizard to generate your report.  This filter can be applied to any report as well as analyses on the Summaries screen (using the same options in the Analysis Wizard).</p>
<p>Happy analyzing!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/enhancement-to-the-sophos-loader-in-analyzer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Counting Emails with Microsoft Exchange 2007 Tracking Logs</title>
		<link>http://www.webspy.com.au/blogs/index.php/counting-emails-with-microsoft-exchange-2007-tracking-logs/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/counting-emails-with-microsoft-exchange-2007-tracking-logs/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 05:45:01 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Email Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Message Tracking Logs]]></category>
		<category><![CDATA[Recipient Count]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=32</guid>
		<description><![CDATA[Today I've been poking at Microsoft Exchange 2007 tracking logs, asking them the very simple question of 'How many emails have I sent?'.

Unforunately, Exchange 2007 tracking logs are not used to simple questions, and are likely to return a complicated and / or misleading answer.

But the confusion it seems, all comes down to definitions. Once you understand these definintions, things start to make a bit more sense.]]></description>
			<content:encoded><![CDATA[<p>Today I&#8217;ve been poking at Microsoft Exchange 2007 tracking logs, asking them the very simple question of &#8216;How many emails have I sent?&#8217;.</p>
<p>Unfortunately, Exchange 2007 tracking logs are not used to simple questions, and are likely to return a complicated and / or misleading answer.</p>
<p>But the confusion it seems, all comes down to definitions. Once you understand these definintions, things start to make a bit more sense.<span id="more-32"></span></p>
<h3>What is an Email?</h3>
<p>If you send an email to one person, you&#8217;ve sent one email. But if you&#8217;ve sent that same email to 500 people, have you sent one email, or 500?  I will take a guess, and say that a large majority of you will want to see 500 in your reports.</p>
<p>Microsoft Exchange 2007 tracking logs contain an excellent field called &#8216;Message ID&#8217;.  If you send an email to someone, that message is uniquely identified by a Message ID that persists though Exchange&#8217;s various functions for the lifetime of the message.</p>
<p>At first glance, it seems that counting Message IDs will give us what we want. But if you send the same email to 500 recipients, all those emails get the same unique message ID. So counting message IDs will show us that only one email has been sent. No good.</p>
<p>Then next obvious step is to count the number of recipients that received the email.</p>
<h3>What is a Recipient?</h3>
<p>The definition of recipient can also get clouded when you start talking about distribution lists. If you send an email to one real person, then that is one recipient. If you send the same email to five real people then that is five recipients. If you send an email to an internal distribution list, the number of recipients is the number of people that are members of that distribution list.</p>
<p>If you send an email to an external distribution list (such as SalesDL@othercompany.com) this will only be recorded as only one recipient, as your Exchange box has no way of knowing how many real people  are members of that DL at the other company.</p>
<h3>How do I count Recipients?</h3>
<p>Again, Exchange Tracking logs contain another excellent field called &#8216;Recipient Count&#8217;.  But don&#8217;t get carried away as this too can be misleading.</p>
<p>Without going into specifics, Exchange has a bunch of internal functions to deal with an entire message transmission. The tracking logs files contain another excellent field called Internal Message ID that identifies each of these processes per-message.</p>
<p>Unfortunately, each Internal Message ID contains its own value for &#8216;Recipient Count&#8217;.  So when you sum the Recipient Count field for a single message, the final result may be much larger than the actual number of real recipients.</p>
<p>To illustrate, WebSpy Vantage imports Recipient Count into a Summary of the same name.  Here is a screenshot of the Recipient Count Summary for one message</p>
<div id="attachment_51" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007recipientcount.png"><img class="size-medium wp-image-51" title="The Exchange 07 'Recipient Count' Summary for a Single Message" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007recipientcount-300x236.png" alt="The Recipient Count Summary for a Single Message" width="300" height="236" /></a><p class="wp-caption-text">The Recipient Count Summary for a Single Message</p></div>
<p>As you can see, there are multiple rows of individual Recipient Counts. The first row, is actually correct. This email was actually sent to 961 people. But there are additional entries where Exchange performed an internal operation with a subset of those messages.  Therefore, summing the Recipient Count field for a message is also no good.</p>
<h3>Counting recipients &#8220;properly&#8221;</h3>
<p>The best way to count recipients is to use WebSpy Vantage to import your logs, then drilldown into a message to the Recipients summary and look at the total number of recipients at the bottom.  Alternatively, add a Count Distinct aggregate for the Recipients summary to any report template.</p>
<p>Here&#8217;s a screenshot of the Recipients summary:</p>
<div id="attachment_36" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007properrecipientcount.png"><img class="size-medium wp-image-36" title="The Recipients Summary showing Total 'Real' Recipients" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007properrecipientcount-300x192.png" alt="The Recipients Summary showing Total 'Real' Recipients" width="300" height="192" /></a><p class="wp-caption-text">The Recipients Summary showing Total &#39;Real&#39; Recipients</p></div>
<p>And here&#8217;s a screenshot showing how to add the aggregate to a report template:</p>
<div id="attachment_37" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007addingnumberofrecipientsaggregate.png"><img class="size-medium wp-image-37" title="Adding the Number of Recipients to a report template" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007addingnumberofrecipientsaggregate-300x196.png" alt="Adding the Number of Recipients to a report template" width="300" height="196" /></a><p class="wp-caption-text">Adding the Number of Recipients to a report template</p></div>
<h3>Counting Total Number of Emails</h3>
<p>The above screenshot will give you a count of all the recipients you have ever sent email to. However, what you really want is a count of recipients <em>per message</em>. You can do this by concatenating the Recipient with the Message ID, and counting the total number of rows. To do this, edit the <em>Number of recipients</em> aggregate column above and enter [Recipient] + [MessageID] in the &#8216;Custom&#8217; edit box.</p>
<div id="attachment_50" class="wp-caption aligncenter" style="width: 422px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/recipientplusmessageid.png"><img class="size-full wp-image-50" title="Recipient Plus MessageID" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/recipientplusmessageid.png" alt="Customizing an aggregate column to concatenate Recipient and MessageID" width="412" height="293" /></a><p class="wp-caption-text">Customizing an aggregate column to concatenate Recipient and MessageID</p></div>
<h3>Exchange 2007 Report Templates</h3>
<p>You can <a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/microsoftexchange2007.zip">download a WebSpy Vantage Templates file here</a> that includes three reports (Email Overview, User Email Activity, and Email Trends) that uses columns such as Number of Emails, Number of Unique Messages and Number of Recipients.<br />
<strong></strong></p>
<p><strong>Tip: </strong>You can convert any email template that has the schema &#8216;All Mail Schemas&#8217; into an Exchange 2007 template in order to report and filter using all the fields available in Exchange 2007.</p>
<p>To do this:</p>
<ol>
<li>Right click an &#8216;All Mail Schema&#8217; email template and select <strong>Duplicate</strong>.</li>
<li>Select Microsoft Exchange 2007 from the schema drop down and click <strong>OK</strong>.</li>
<li>When you edit the nodes in your new template, you will have access to all the fields that Exchange 2007 records.</li>
</ol>
<p>Cheers!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/counting-emails-with-microsoft-exchange-2007-tracking-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Date Modifiers in File Masks &#8211; New Features</title>
		<link>http://www.webspy.com.au/blogs/index.php/13/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/13/#comments</comments>
		<pubDate>Fri, 06 Mar 2009 03:40:24 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Date Modifiers]]></category>
		<category><![CDATA[File Masks]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Tasks]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=13</guid>
		<description><![CDATA[We&#8217;ve recently added two new features to WebSpy Vantage (all flavours) to deal with a specific issue setting up automated importing tasks using date modifiers in file masks.
A common setup is to have a task that creates a storage each month, then a separate task that runs at the end of each day – say [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve recently added two new features to WebSpy Vantage (all flavours) to deal with a specific issue setting up automated importing tasks using date modifiers in file masks.</p>
<p>A common setup is to have a task that creates a storage each month, then a separate task that runs at the end of each day – say at 10pm, to imports new hits into the storage.  <span id="more-13"></span>The issue here is that at the end of the month, hits between 10pm and 12pm will never be imported, as the next time the task runs it will be dealing with next month’s storage.</p>
<p>As long as your log files contain the date in the file name, you can use <a title="Using Date Modifiers" href="http://www.webspy.com.au/support/knowledgebase/viewKBArticle.aspx?id=119" target="_blank">date modifiers</a> in file masks to import the appropriate log files. Date Modifiers are used to create file masks such as &#8216;access_200902*.log&#8217;, or &#8216;access_20090203.log&#8217; that will cull down the number of log files to import. This is much faster than using date filters (specified on the filters page).</p>
<h2>The Issue:</h2>
<p>The issue is that a log file location in a storage can only have one file mask, and this cannot (until now) not be modified by task actions.  So you cannot specify a new task on the first of each month to import yesterday&#8217;s log file into last month&#8217;s storage, if that storage already has a file mask to only import the current day&#8217;s log file.</p>
<h2>The two solutions:</h2>
<h3>1. Save the literal file mask into the storage when the storage gets created.</h3>
<p>This option allows you to specify a file mask such as  access_%[yyyyMM]* in the ‘Import logs into new storage’ task, but when each storage is created, the actual file mask that gets saved into the storage includes the literal month and year values such as access_200902*</p>
<p>This way you can specify an ‘Import new hits’ job, and even if that job runs in the next month,  ONLY log files from the desired month will be checked for new hits.</p>
<p>To access this option:</p>
<ol>
<li>Go to the <strong>Tasks </strong>screen and edit your ‘Import logs into new storage’ action</li>
<li>Go to the Input Selection page</li>
<li>Select your log folder (not individual files) and click <strong>Edit</strong></li>
<li>Check the ‘Save literal date into mask’ check box</li>
<div id="attachment_14" class="wp-caption aligncenter" style="width: 420px"><img class="size-full wp-image-14" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/save-literal-date-into-mask.jpg" alt="Save literal date into file mask option" width="410" height="365" /><p class="wp-caption-text">Save literal date into file mask option</p></div>
<p>Downside of this option is that in my ‘monthly storage’ example, all 31 log files for the month will be checked for new hits.</p>
<h3>2. Override a storage’s file mask using the Import New Hits task action.</h3>
<p>The Select Storage dialog that appears when configuring an ‘Import new hits into existing storage’ action now has a new option to override a storage’s file mask when the task runs.</p>
<div id="attachment_15" class="wp-caption aligncenter" style="width: 476px"><img class="size-full wp-image-15" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/override-file-mask.jpg" alt="Over-ride the file mask" width="466" height="419" /><p class="wp-caption-text">Override the file mask option</p></div>
<p>This allows you to configure a task that runs on the first day of each month to import only yesterday’s log file into last month’s storage (need to add last month’s storage using the <strong>Add</strong> button, and specify the appropriate date modifier to access it – e.g. “%[-1m, yyyyMM] My Monthly Storage”).</p>
<p>This will only check one file for new hits and will finish the import job faster than option 1 (using the monthly storage example).</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/13/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to report on who accessed a file or folder</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-to-report-on-who-accessed-a-file-or-folder/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-to-report-on-who-accessed-a-file-or-folder/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 08:19:07 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Windows Event Logs]]></category>
		<category><![CDATA[Event Logs]]></category>
		<category><![CDATA[file access reporting]]></category>
		<category><![CDATA[File and Folder Auditing]]></category>

		<guid isPermaLink="false">http://scottglew.wordpress.com/?p=10</guid>
		<description><![CDATA[I'm frequently asked about the best way to setup and report on file or folder accesses. In other words, I have a bunch of confidential files sitting on my network and I want to know who is accessing them. So here it is (you might want to grab a coffee first!).]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m frequently asked about the best way to setup and report on file or folder accesses. In other words, I have a bunch of confidential files sitting on my network and I want to know who is accessing them.</p>
<p>So here it is (you might want to grab a coffee first!).<span id="more-25"></span></p>
<p>Unless you have a sophisticated end point security or file auditing solution in place, you&#8217;re pretty much limited to the quality of data found in your Windows Security Event log. By default, accesses to your confidential files are not going to trigger any entries to be written to the Event log. You first need to setup file or folder auditing.</p>
<p>WebSpy have written a nice article to help you out with this: <a title="Managing Event Logs" href="http://www.webspy.com/resources/whitepapers/2008%20WebSpy%20Ltd%20-%20Managing%20Event%20Logs.pdf" target="_blank">Managing Event Logs<br />
</a></p>
<p>Personally, I&#8217;m running Windows Vista SP1.  So I first turned on Object Access auditing by going to <strong>Control Panel | Administrative Tools | Local Security Policy | Local Policy | Audit Policy</strong> and set<em> Audit Object Access</em> for <em>Success </em>and <em>Failure</em>.</p>
<div id="attachment_11" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-11" title="localsecuritypolicy" src="http://scottglew.files.wordpress.com/2009/02/localsecuritypolicy.jpg" alt="Windows Vista Local Security Policy" width="450" height="322" /><p class="wp-caption-text">Windows Vista Local Security Policy</p></div>
<p>In Windows Explorer, navigate to the folder or files to audit, then <strong>Right-click | Properties | Security | Advanced | Auditing </strong>and click Continue when Vista&#8217;s User Access Control gets in the way.  Here you get the option to add Users or Groups to the audit policy. So if you only want to know when Joe Bloggs access the file/folder, then only add Joe Bloggs. If you want to know when anyone accesses the file/folder then add your entire company.</p>
<p><img class="alignnone size-full wp-image-12" title="Audit Entries 1" src="http://scottglew.files.wordpress.com/2009/02/auditentries1.jpg" alt="Audit Entries 1" width="381" height="483" /></p>
<p>Scroll&#8230;.</p>
<p><img class="alignnone size-full wp-image-14" title="Audit Entries 2" src="http://scottglew.files.wordpress.com/2009/02/auditentries21.jpg" alt="Audit Entries 2" width="377" height="479" /></p>
<p>Click <strong>OK </strong>and apply the changes. If applying this to a folder, take note of the setting to &#8216;apply the auditing entries to containers within this container&#8217; at the bottom and use as required.</p>
<p>Congratulations. That&#8217;s the auditing setup. Once people start accessing these files(s), the auditing information will get recorded to the Security Event Log on the machine that hosts the file(s) in question.</p>
<p>The next step is to import the Windows Security log into your flavour of WebSpy Vantage. I&#8217;m using Vantage Ultimate, but the steps are the same for Premium and Giga.</p>
<ol>
<li>Run Vantage (as Administrator if on Vista)</li>
<li>Go to the <strong>Storages </strong>tab and click <strong>Import Logs</strong></li>
<li>Run through the Import Wizard with these settings:</li>
</ol>
<ul>
<li>Storage: New storage
<div id="attachment_17" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-17" title="Storages Page" src="http://scottglew.files.wordpress.com/2009/02/import11.png" alt="Storages Page" width="450" height="369" /><p class="wp-caption-text">Input Dialog: Storages Page</p></div></li>
<li>Input Type: Windows Event Log
<p><div id="attachment_18" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-18" title="Input Type Page" src="http://scottglew.files.wordpress.com/2009/02/import2.png" alt="Input Type Page" width="450" height="369" /><p class="wp-caption-text">Input Dialog: Input Type Page</p></div></li>
<li>Loader Selection: Microsoft</li>
<p><div id="attachment_19" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-19" title="Loader Selection" src="http://scottglew.files.wordpress.com/2009/02/import3.png" alt="Loader Selection" width="450" height="369" /><p class="wp-caption-text">Input Dialog: Loader Selection</p></div>
<li>Input Selection: <strong>Add </strong><br />
Select either local computer, or multiple computers, enter authentication details and Click &#8216;Filter Event Logs&#8217;. Check the &#8216;Security&#8217; Log and click <strong>OK</strong>.</p>
<div id="attachment_20" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-20" title="Input Selection Page - Adding Event Logs" src="http://scottglew.files.wordpress.com/2009/02/import4.png" alt="Input Selection Page - Adding Event Logs" width="450" height="377" /><p class="wp-caption-text">Input Dialog: Input Selection Page - Adding Event Logs</p></div></li>
<li>Click <strong>OK</strong> to start the import.</li>
</ul>
<p>If there are any issues with the import process, consult these three WebSpy Knowledgebase articles to do with issues importing event logs:</p>
<ul>
<li> <a title="Event Log Troubleshooting (Know Issues and Fixes)" href="http://www.webspy.com.au/support/knowledgebase/viewKBArticle.aspx?id=159" target="_blank">Event Log Troubleshooting (Known Issues and Fixes)</a></li>
<li><a title="Importing Event Logs from machines on a different domain" href="http://www.webspy.com.au/support/knowledgebase/viewKBArticle.aspx?id=156" target="_blank">Importing Event Logs from machines on a different domain</a></li>
<li><a title="Required Services for Event Log Importing" href="http://www.webspy.com.au/support/knowledgebase/viewKBArticle.aspx?id=157">Required Services for Event Log Importing</a></li>
</ul>
<p>The first article came in handy for me as I’m running on Vista and in order to import from the Local Security log, you need to run Vantage as Administrator. To do this, go to C:\Program Files\WebSpy\Vantage Ultimate 2.1\ right-click the WebSpy.Vantage.exe and select ‘Run as Administrator’.</p>
<p>Once data has been imported into your storage, check it out on the <strong>Summaries </strong>screen.</p>
<p>To to the <strong>Summaries </strong>Tab, Run an Analysis on your new storage (ad-hoc analysis will do) , and go to the <strong>Category </strong>Summary. There should be some ‘File System’ items there assuming the file has been accessed since setting up file auditing. You can then drilldown to <strong>Event Type </strong>to see ‘Audit Success’ or ‘Audit Failure’. To see who has Successfully accessed a certain file, drilldown into the ‘Audit Success’ item.</p>
<p>Unfortunately the good stuff is buried in the ‘<strong>Message</strong>’ field, which you can only access in the<strong> Individual Records</strong> view. This is because the Message field in Event logs is free form and could vary wildly resulting in millions of unique items. A Message Summary has therefore been excluded from a default ad-hoc analysis for very good performance reasons.</p>
<p>Event logs can also be quite verbose, and if you drilldown to Individual Records at this stage, you’ll see lots of messages like ‘<em>A handle to an object was requested</em>’ which probably isn’t of any great value from a reporting perspective. One way to filter out this noise is by <strong>Event ID.</strong></p>
<p>I’ve discovered that the events that correspond to ‘<em>An attempt was made to access an object</em>’ have the ID <strong>4663. </strong>(One day I&#8217;ll create an alias to map Event IDs to their meaningful description. If you come across a good  resource I can use for this, let me know!).  So go to the <strong>Event ID </strong>summary and drilldown into <strong>4463 </strong>to the <strong>Individual Records </strong>view.</p>
<p>Once you’re at Individual Records, you can hover over the message field to get details. You can also use the find edit box to search for a particular user or file:</p>
<p><div id="attachment_25" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-25" title="Drilldown into Successful File System Accesses (Event ID 4663)" src="http://scottglew.files.wordpress.com/2009/02/drilldowntofilesystemevents.png" alt="Drilldown into Successful File System Accesses (Event ID 4663)" width="450" height="280" /><p class="wp-caption-text">Drilldown into Successful File System Accesses (Event ID 4663)</p></div>
<p>You can export this view To Word Document, HTML, Text or CSV by right-clicking the <strong>Individual Records</strong> summary and clicking <strong>Export</strong>.</p>
<p>You can also create a report template to access this same information, but as there is no ‘Message’ summary to choose from, you need to use the Custom expression options, both when adding a column to a node in a Template, and when specifying your filter.</p>
<p>To add a column to a report that displays an Event Message:</p>
<ol>
<li>Go to the <strong>Reports </strong>Tab and click <strong>New Template</strong></li>
<li>Create an Analysis template based on the ‘All Windows Event Schemas’ schema</li>
<li>Click <strong>New Node </strong>and click the <strong>Advanced </strong>button to launch the Advanced editor.</li>
<li>On the General page, delete any existing Key columns and select <strong>Add | Key</strong>. In the Custom Expression section enter <strong>[Message]</strong> (include the square brackets) and click <strong>OK</strong>.</li>
</ol>
<p>To filter the report:</p>
<ol>
<li>Go to the <strong>Filters </strong>page of the New Node dialog (alternatively you can specify this filter in for all nodes using the Template Properties dialog)</li>
<li>Click <strong>Add | Field Value Filter</strong>. Select Category from the Summary drop down, and click <strong>Add</strong>. Enter ‘File System’ (without the quotes) and click OK. Click OK to add the filter.</li>
<li>Click <strong>Add | Field Value Filter</strong>. Select Event ID from the Summary drop down and click <strong>Add</strong>. Enter &#8216;4463&#8242; (without the quotes) and click OK.</li>
<li>To filter on the Message field, Select <strong>Add | Manual Filter Expression</strong>.</li>
<li>Enter the expression:</li>
<li>[Message] LIKE “<em>text to filter for</em>”<br />
Change ‘text to filter for’ to the user or file that you want to search for. If you want to search for multiple strings, repeat the above expression separated by an AND or an OR, and place brackets wherever it makes sense. For example:</p>
<ul>
<li>[Message] LIKE “scottg” AND [Message] LIKE “.avi”<br />
Will filter for all .avi files that scottg has accessed.</li>
<li>[Message] LIKE “scottg” OR [Message] LIKE “.avi”<br />
Will filter for any file that scottg has accessed and any avi that anyone has accessed.</li>
<li>([Message] LIKE “scottg” AND [Message] LIKE “.avi”) OR [Message] LIKE “andrew”<br />
Will filter for any all avi files that scottg has accessed and any file that Andrew has accessed.</li>
</ul>
</li>
<li>You can add the individual filters using Add | Manual Filter Expression multiple times, and then using the Manual Filter Expression editor at the bottom to change ANDs to Ors and place brackets appropriately, like so:
<p><div id="attachment_26" class="wp-caption alignnone" style="width: 460px"><img class="size-full wp-image-26" title="Filtering for File Access Events by particular users" src="http://scottglew.files.wordpress.com/2009/02/messagefilter.png" alt="Filtering for File Access Events by particular users" width="450" height="337" /><p class="wp-caption-text">Filtering for File Access Events by particular users</p></div></li>
<li>Right-click the <em>Manual Filter Expression </em>edit box and select <strong>Validate </strong>to make sure everything is good with the expression.</li>
<li>Modify chart settings, sorting, etc as appropriate.</li>
</ol>
<p><a title="File Access Report Template" href="http://www.webspy.com/resources/reporttemplates/FileAccessReportTemplate.zip">Here&#8217;s the resulting report template for you</a>, but please note that it includes the filter above (events for the user&#8217;s  &#8216;Asa&#8217; and &#8216;Scottw&#8217;), so you will need to modify the filter and enter the users or files you want to filter on. Just use the user’s windows login name, and/or the name of the file.  Alternatively, remove the filter altogether if you want to see all File Audit events.</p>
<p>That&#8217;s it! Now run your report, automate it using the Tasks screen, and your set!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-to-report-on-who-accessed-a-file-or-folder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

