<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebSpy Blog&#187; drilldowns &#8211; WebSpy Blog</title>
	<atom:link href="http://www.webspy.com.au/blogs/index.php/tag/drilldowns/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webspy.com.au/blogs</link>
	<description>For when WebSpyrians have something to say.</description>
	<lastBuildDate>Fri, 09 Dec 2011 01:18:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Creating and Analyzing SonicWALL Log Files</title>
		<link>http://www.webspy.com.au/blogs/index.php/creating-and-analyzing-sonicwall-log-files/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/creating-and-analyzing-sonicwall-log-files/#comments</comments>
		<pubDate>Wed, 22 Dec 2010 07:28:52 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[bandwidth]]></category>
		<category><![CDATA[Categories]]></category>
		<category><![CDATA[drilldowns]]></category>
		<category><![CDATA[Internet Usage]]></category>
		<category><![CDATA[Kiwi]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Sites]]></category>
		<category><![CDATA[SonicWall]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[video]]></category>
		<category><![CDATA[Web Reports]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2463</guid>
		<description><![CDATA[I&#8217;ve put together a couple of quick videos to show you how to configure logging on your SonicWALL appliance, and how to import and analyze these log files in WebSpy Vantage.
You can also read through these steps on this page:  Analyzing SonicWALL log files with WebSpy.

Creating and Importing SonicWALL log files

Analyzing SonicWALL log files

We [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve put together a couple of quick videos to show you how to configure logging on your SonicWALL appliance, and how to import and analyze these log files in WebSpy Vantage.</p>
<p>You can also read through these steps on this page:  <a title="Analyzing and Reporting on SonicWALL log files" href="http://www.webspy.com/vendors/sonicwall/howto.aspx" target="_blank">Analyzing SonicWALL log files with WebSpy</a>.</p>
<p><span id="more-2463"></span></p>
<h3>Creating and Importing SonicWALL log files</h3>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgo3vbQI" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="300" src="http://blip.tv/play/hLYlgo3vbQI" allowfullscreen="true"></embed></object></p>
<h3>Analyzing SonicWALL log files</h3>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="300" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgpa_OgA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="480" height="300" src="http://blip.tv/play/hLYlgpa_OgA" allowfullscreen="true"></embed></object></p>
<p>We intend to make some SonicWALL specific report templates available on our <a title="How to Report on SonicWALL Log Files" href="http://www.webspy.com.au/vendors/sonicwall/" target="_blank">SonicWALL how to</a> page soon.</p>
<p>Until then, feel free to create your own templates, or modify our existing web reports to include the extra goodies contained in the SonicWALL logs.</p>
<p>TIP: To modify an existing web report, right-click the report and choose ‘Duplicate template’. Then choose the “SonicWall Web” schema. You’ll then have a report template that you can modify to include all the SonicWALL summaries, such as Categories, and Source and Destination Interface.</p>
<p>If you need some assistance getting the report(s) you need, feel free to contact me, or support@webspy.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/creating-and-analyzing-sonicwall-log-files/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>8 Reasons NOT to Use Microsoft Forefront TMG&#8217;s Reporting</title>
		<link>http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/#comments</comments>
		<pubDate>Mon, 08 Feb 2010 06:48:39 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[customize]]></category>
		<category><![CDATA[drilldowns]]></category>
		<category><![CDATA[Filtering]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[limitations]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[productivity]]></category>
		<category><![CDATA[report distribution]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[secure report distribution]]></category>
		<category><![CDATA[sub-domains]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[TMG Reporting]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1181</guid>
		<description><![CDATA[I've been having a look through the reporting functionality included in Microsoft Forefront Threat Management Gateway to find that not much has changed from ISA Server 2006. There is some new information regarding the newly implemented URL categorization and threat management technology, but there is very little flexibility or customization for those with reporting requirements beyond general overviews cluttered with irrelevant information. Here is what I consider to be the 8 main limitations of Microsoft Forefront TMG's reporting functionality.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been having a look through the reporting functionality included in Microsoft Forefront Threat Management Gateway to find that not much has changed from ISA Server 2006. There is some new information regarding the newly implemented URL categorization and threat management technology, but there is very little flexibility or customization for those with reporting requirements beyond general overviews cluttered with irrelevant information.<span id="more-1181"></span></p>
<p>Here&#8217;s a quick video outlining some of the differences between TMGs Reporting, and what can be achieved using WebSpy Vantage. The video does not illustrate all the limitations outlined below, so please read on.<br />
<object width="400" height="255" data="http://blip.tv/play/hLYlgcLyGAA" type="application/x-shockwave-flash"><param name="src" value="http://blip.tv/play/hLYlgcLyGAA" /><param name="allowfullscreen" value="true" /></object></p>
<h2>Whats is in the Forefront TMG report?</h2>
<p>The default TMG report contains the following sections</p>
<ul>
<li>Summary</li>
<li>Web Usage</li>
<li>Application Usage</li>
<li>Traffic and Utilization</li>
<li>Security</li>
<li>Malware Protection</li>
<li>URL Filtering</li>
<li>Network Inspection System</li>
</ul>
<p>Each section contains overviews such as &#8216;Top users&#8217; and &#8216;Top Sites&#8217;.</p>
<p>If your reporting requirements can be satisfied with these overviews &#8211; that&#8217;s great! Unfortunately, when you start thinking about what system administrators and other people in your organization actually need to make informed decisions, this report is quite limiting.</p>
<h1>The 8 Limitations of Microsoft Forefront TMG&#8217;s Reporting</h1>
<p>Here is what I consider to be the<strong> </strong>8 main limitations of Microsoft Forefront TMG&#8217;s reporting functionality.</p>
<h2>1. No Drilldowns</h2>
<p>Want to see the sites that the top 5 users accessed? Want to see the users that downloaded the most traffic from youtube? These are fairly standard reporting requirements that simply cannot be achieved using the inbuilt TMG reporting.</p>
<p>WebSpy Vantage lets you either interactively drilldown into a user or site, or produce a regular report that includes further details about what your top users have actually been up to.</p>
<h2>2. No Filtering</h2>
<p>When you generate a report in TMG, you can only filter the report by a date range. There is no way to filter out anonymous (unauthenticated) traffic or exclude traffic coming from advertising servers (such as doubleclick and 2mdn.net) that tend to dominate most of the top 10 sites.</p>
<p>This can easily be achieved using WebSpy&#8217;s software. Check out my<a href="http://www.webspy.com.au/blogs/index.php/how-to-remove-clutter-from-your-web-reports/" target="_blank"> video on how to remove clutter from your web reports</a>.</p>
<h2>3. No Customization</h2>
<p>Customization of each overview in the TMG report is limited to the number of items to show (e.g. top 5 or top 50 users), and the sort order (Incoming Bytes, Outgoing Bytes, Requests and Total Bytes).</p>
<p>What about the time a user spent browsing the web, or the number of users that visited a specific site? There is no way to add custom columns such as total browsing time, average session time, or number of users/sites/IPs to the report tables.</p>
<p>Or say you simply want to change your top users chart from a bar to pie to easily see the percentage used. Nope sorry!</p>
<p>If you do make one of the two available customizations in a TMG report, you then get the annoying Apply / Discard message to save changes to the configuration database.</p>
<p>All of these customizations can be achieved using WebSpy Vantage, and it doesn&#8217;t touch your TMG server to apply a change to a report.</p>
<h2>4. Limited Report Distribution</h2>
<p>When you generate a report, you get the option to email it to a specific email address. What if you would like to create a report for every department, and then email it to the managers of each department? Or better yet, host the report on a secure web server where department managers can log in and view their reports?</p>
<p>WebSpy Vantage Ultimate comes with a secure &#8216;Web Module&#8217; specifically for this purpose and managers still receive a link to the report via email.</p>
<h2>5. Cluttered &#8216;Top Sites&#8217; List</h2>
<p>The &#8216;Top sites&#8217; list can become particularly cluttered due to the inclusion of sub-domains. I don&#8217;t want to mentally add up the size values from farm1.static.flickr.com, farm2.static.flickr.com, and farm3.static.flicr.com &#8211; I just want to know how much was downloaded from flickr.com.</p>
<p>This is compounded by the inability to exclude sites that are merely placing advertising banners on the actual sites users are visiting (as mentioned in the &#8216;No Filtering&#8217; limitation above).</p>
<p>WebSpy Vantage breaks URLs down into separate components and lets you analyze each part separately. Look at the <strong>Site Domains</strong> summary to remove sub-domains and see <em>only </em>flickr.com. Or perhaps you want to see the keywords a user entered into search engines like Google? Or perhaps the top pages accessed within a website? No problem. Just include the <strong>Site Keywords</strong> or <strong>Site Resource</strong> summaries in your Vantage reports.</p>
<h2>6. No Grouping or Aliasing</h2>
<p>There is no way to group users into departments or locations, or IP addresses into subnets, or extensions such as .html, .pdf or .exe into file types. The ability to group and represent raw log data in more meaningful ways, as offered by WebSpy Vantage, can increase the value of a report tremendously.</p>
<h2>7. No Productivity Assessment</h2>
<p>One of the major features introduced in TMG since ISA Server 2006 is the included URL categorization technology.</p>
<p>Although the TMG report gives you an overview of the categories that have been visited, the report does not use this information to display a productivity assessment for your users.</p>
<p>WebSpy Vantage not only provides this assessment, but also the ability to customize the categories that are deemed productive as this can vary wildly depending on the industry and organization.</p>
<h2>8. Not browser independent</h2>
<p>This is a minor limitation that can be a major annoyance. The report that TMG produces is a HTML report that only displays correctly in Internet Explorer. As Forefront TMG is a Microsoft product, this is not exactly surprising, but still very annoying if IE is not your default browser.</p>
<h2>How to get awesome reports from Forefront TMG</h2>
<p>If you have had personal experience with any of the above limitations, you&#8217;ve probably been hunting for an alternative solution. I strongly recommend checking out the <a title="WebSpy Vantage" href="http://www.webspy.com/products/vantage/default.aspx" target="_blank">WebSpy Vantage</a> range of products, and if you would like secure report distribution via the &#8216;Web Module&#8217;, <a title="Vantage Ultimate" href="http://www.webspy.com/products/vantage/ultimate/vantageultimate.aspx" target="_blank">Vantage Ultimate</a> is what you are after.</p>
<p>If you agree or disagree with anything in this article, I encourage you to leave your thoughts in the comments.</p>
<p>Cheers!</p>
<p>Scott</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

