Our website requires you install or enable flash player for full experience, you can download flash player by clicking here.
Make sure you also have javascript enabled so that flash player & menus work correctly.

Get Adobe Flash player

What would you like to monitor?

For when WebSpyrians have something to say.

Archive for the ‘Firewall Analysis’ Category

Creating and Analyzing SonicWALL Log Files

Wednesday, December 22nd, 2010

I’ve put together a couple of quick videos to show you how to configure logging on your SonicWALL appliance, and how to import and analyze these log files in WebSpy Vantage.

You can also read through these steps on this page: Analyzing SonicWALL log files with WebSpy.

(more…)


Detecting a distributed reflected DNS attack

Friday, December 10th, 2010

The other night as I was getting ready to sleep, I received an email from the host of my personal Linux VPS saying that I had exceeded my monthly transfer quota. I didn’t pay much mind to the warning, as the excess transfer was insignificant, and at that time I was too tired to care. I closed my email, got into bed and fell asleep.

(more…)


Reporting on Astaro Security Gateway

Friday, December 10th, 2010

Astaro Security Gateway devices are capable of producing some very detailed log files including full URLs, usernames, categories, block action and reason which gives you some great reporting options in WebSpy Vantage.

Take a look at our dedicated Astaro pages to get an idea of what can be achieved when analyzing Astaro Web Gateway log files with WebSpy Vantage.

I’ve created some quick videos to show you how to enable the correct logging options on the Astaro Security Gateway appliance, how to import these log files into Vantage, and analyze the data on the Summaries screen. (more…)


Watch your TMG’s waist line. Switch log format and reduce fat now!

Wednesday, October 27th, 2010

We often recommend customers using Microsoft ISA or TMG switch their logging to W3C text file, in order to get the best possible import speed, and also because the text logs are much easier to access from a remote machine (see my previous article on accessing TMG’s SQL Express Log database). Logging to the default MSDE or SQL Express databases also requires more resources in terms of processor utilization, memory consumption and disk I/O.

But there is another advantage to switching to text. They take up considerably less disk space. Here are some figures:

(more…)


Vantage Update 2.2.0.55 (Clearswift, Palo Alto Networks, WatchGuard and more)

Tuesday, October 12th, 2010

We’ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats. (more…)


Microsoft Forefront TMG logs size fields the wrong way around

Thursday, July 29th, 2010

If you’re using Microsoft Forefront Threat Management Gateway, there is a bug in the logging that causes Bytes Sent and Bytes Received to be logged in reverse. This seems to only affect the Web Proxy logs – both SQL and W3c . We noticed in a few web reports, that people were generally uploading a lot more than they were downloading. So we checked the logs and verified the buggy behavior: (more…)


Why there is so much anonymous traffic in Microsoft TMG and ISA logs

Monday, July 19th, 2010


One of the most common questions we get asked by users of Microsoft TMG and ISA is why there is so much traffic attributed to the Anonymous user. Even though unauthenticated access to the web has been disabled, they still see the ‘Anonymous’ user as one of the top users in their reports.

So let’s use WebSpy Vantage to drill into that Anonymous user and find out what is going on. (more…)