Our website requires you install or enable flash player for full experience, you can download flash player by clicking here.
Make sure you also have javascript enabled so that flash player & menus work correctly.

Get Adobe Flash player

What would you like to monitor?

For when WebSpyrians have something to say.

Archive for the ‘WebSpy’ Category

Why there is so much anonymous traffic in Microsoft TMG and ISA logs

Monday, July 19th, 2010


One of the most common questions we get asked by users of Microsoft TMG and ISA is why there is so much traffic attributed to the Anonymous user. Even though unauthenticated access to the web has been disabled, they still see the ‘Anonymous’ user as one of the top users in their reports.

So let’s use WebSpy Vantage to drill into that Anonymous user and find out what is going on. (more…)


Video: How to use WebSpy Vantage to report on IronPort log files

Friday, June 18th, 2010

I’ve produced a video on how to use WebSpy Vantage to report on IronPort’s Web Security Appliance’s access log files. It is quite a detailed look at the key tasks involved in setting up and using WebSpy Vantage with IronPort WSA access logs, and is therefore divided into several parts. The videos take you through the following activities:

  • How to import your log files and explore the information recorded by IronPort using the Summaries screen
  • How to open the customized IronPort Report Templates and Aliases
  • How to generate reports
  • How to import your organizational structure and report on departments
  • How to setup the Web Module and publish reports

(more…)


Accessing Microsoft Forefront TMG’s Log Files (SQL Express)

Friday, June 11th, 2010

If you need to analyze and report on Microsoft Forefront Threat Management Gateway log files, the most common stumbling block is enabling access to the default SQL Express databases that contains the firewall and web proxy log files.

The log databases are stored in an SQL Express instance named MSFW. By default these databases cannot be accessed by a remote computer. I’d first like to say that we recommend changing TMG’s logging to W3C text files, as these logs are about 5-6 times faster to import, and you don’t need to worry about the steps below.

But if you need to stick with the SQL Express logging, here are the basic steps to enable access to the logs from a remote computer: (more…)


How to report on bandwidth utilization using Cisco devices

Thursday, May 27th, 2010

Today I was speaking to a customer that had the following reporting request:

“I would like to know how much of my bandwidth is being eaten by each protocol. I will then use this information to determine if circuit may need to be increased due to increased traffic”.

This customer was collecting syslog messages from a Cisco Firewall, then using WebSpy Vantage to generate reports. In theory, this sounds like a fair plan. Unfortunately, the Cisco Firewall logs many different types of messages. Some to do with denied packets, some to do with authentication, some for vpn and so on. The information contained within each message changes. Some events include the size information that is required for any type of bandwidth assessment and some don’t. Correlating the required events to get any sort of accurate ‘bandwidth’ representation is a bit of a nightmare.

Fortunately, there’s a simpler method. (more…)


How WebSpy Vantage uses your CPUs

Friday, May 21st, 2010

I’m frequently asked how WebSpy Vantage utilizes a systems CPU resources. Sometimes you may notice Vantage utilizing 100% of your machine’s CPU power, and other times it will be hardly touched. So here is an overview of how the software works internally so you can understand when your CPUs will and won’t be pushed. (more…)


Vantage Update 2.2.0.43

Thursday, May 20th, 2010

We’ve just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module.

This is a great update for Vantage Ultimate users as we’ve introduced a new feature/tab into the Web Module called ‘Dynamic Reports’.

If you’re publishing the same report to the Web Module each day, you can use the Dynamic Reports tab to select a date range and a department (or whatever organizational groups you have defined) and the Web Module will collate all the daily reports that match that filter into one report. This allows you to report on entire week, month or year by simply ‘reporting on reports’, rather than reporting months of raw storage data.

Here’s the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).

Application Changes

  • Added Dynamic Reports feature to the Web Module.
  • Rewrote the Web Module transfer protocol. New protocol adds version checking, connection checking, and integrity checking for high latency environments.
  • Purge data from storage task no longer prevents importing new hits when all data is removed from an input within a storage.
  • IPv6 addresses now show IPv4-mapped addresses as plain IPv4 addresses in summaries.
  • IPv6 and IPv4 addresses are now freely interchangable in filter expressions.
  • Fixed IPv6 drilldowns on the Summaries screen
  • SQL inputs can now be resumed from the previous position. Previously any input that was partially imported would be skipped when importing new hits.
  • Template-based analysis has been fixed, no longer results in blank/non-existent analysis.
  • Added new string manipulation functions to expression language; Contains, StartsWith, EndsWith, IndexOf.

Loader Changes

  • Astaro: Now checks that the ID field is present in a line before attempting to read it.
  • Barracuda Web Filter: Added this format to replace Spy Filter.
  • BlueCoat Proxy SG W3C: Added support for gmttime, timestamp, x-bluecoat-surfcontrol-is-denied and x-bluecoat-transaction-id.
  • ClearSwift: Added a new loader group for ClearSwift that includes the MimeSweeper loaders
  • ClearSwift SECURE Web Gatway: Now supported with the Web Appliance loader
  • Clearswift Web Appliance: User summary displays Source IP if Username is blank.
  • IronPort WSA: Fixed memory usage issues.
  • Microsoft FTMG: Added category name lookup to SQL loader.
  • Microsoft FTMG: No longer fails to import lines where the rule field contains square brackets.
  • Microsoft FTMG: URL Category field is now a string instead of an integer. Added URL Categorization Reason field.
  • Microsoft FTMG: Fixed memory usage issues.
  • Microsoft IIS W3C: No longer hangs or crashes when loading a file that isn’t IIS W3C.
  • NetAsq: Added support for srcname field. The Username summary is populated with user first, and then srcname if user is blank. The User summary is also now populated with Source IPs if the Username summary is blank.

To update WebSpy Vantage, simple select Tools | Check for updates.

To update the Web Module, login to the Web Module server, right-click the WebSpy system tray icon, and select Check for updates.

As always, please contact us if you have any issues or questions.


Dedicated WebSpy and Forefront TMG pages – Everything you need to know about TMG Log Reporting

Wednesday, May 12th, 2010

forefront_v_webMicrosoft Forefront Threat Management Gateway (TMG) popularity is starting to pick up. WebSpy added support for analyzing and reporting on TMG logs even before the public release and have been improving our compatibility ever since.

(more…)