<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebSpy Blog&#187; IronPort &#8211; WebSpy Blog</title>
	<atom:link href="http://www.webspy.com.au/blogs/index.php/tag/ironport/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webspy.com.au/blogs</link>
	<description>For when WebSpyrians have something to say.</description>
	<lastBuildDate>Fri, 09 Dec 2011 01:18:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Vantage Update 2.2.0.68 (Exchange 2010, Juniper and IronPort Traffic Logs, and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 02:18:27 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[fixes]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Squid]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2494</guid>
		<description><![CDATA[We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.
Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as [...]]]></description>
			<content:encoded><![CDATA[<p>We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.</p>
<p>Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as JunOS (Juniper) Traffic Logs, IronPort Traffic Monitor Logs and Squid Syslog.<span id="more-2494"></span></p>
<p>We&#8217;ve also included an experimental feature to allow multiple instances of WebSpy Vantage to run on the same operating system. The goal here is to run multiple reports at the same time using multiple instances of the application. To do this, we have also included a second experimental feature to disable storage locking. This allows multiple instances of Vantage to read from the same storage at once. These features can only be enabled by including a config file next to the Vantage&#8217;s executable. <a title="Running Multiple=">More on this feature here</a>.</p>
<p>Here&#8217;s the full list of changes:</p>
<h3>Application Changes</h3>
<ul>
<li>New: Added suffix option to Import Windows Users wizard in Aliases.</li>
<li>New: Date modifiers now supports h for hour and n for minute, e.g. %[-2h,yyyyMM - HH].</li>
<li>New: Added tracing to storage publish task.</li>
<li>Experimental: Multiple instances of Vantage can now be run simultaneously, by adding the multipleInstance key to the application config file.</li>
<li>Experimental: Storage locking can be turned off to allow multiple instances of Vantage to run reports on a single storage simultaneously. This is done by adding the storageLocking key to the application config file.</li>
<li>Fix: Import Organization merge options now appends attributes if keep existing user details is selected, and replaces attributes if update user details from the directory is selected.</li>
<li>Fix: Import Organization merge no longer replaces user&#8217;s passwords.</li>
<li>Fix: Fixed issue where no results were returned when filtering on time less than one day – such as past n hours.</li>
<li>Fix: Storages are no longer duplicated in the Import new hits task dialog.</li>
<li>Fix: Fixed issues where the Site Domain summary included sub-domains for European domains (.fr, .be etc).</li>
<li>Fix: SQL server inputs now commit correctly if the user edits the input and only changes the port number.</li>
</ul>
<h3>Loader Changes</h3>
<ul>
<li>New: IronPort Traffic Monitor Logs.</li>
<li>New: Juniper JunOS Traffic Logs (SRX).</li>
<li>New: Microsoft Exchange 2010.</li>
<li>New: Squid Syslog.</li>
<li>Improved: Astaro Security Gateway: Added support for an additional different syslog header.</li>
<li>Improved: SonicWall: Split syslog format into Web and Firewall schemas, added support for User field, string-type Category field and split Protocol field.</li>
<li>Fix: Microsoft FTMG: Changed type of Object Source field in from Int32 to String. Users will need to clear/field select/reload their storages before this change will apply.</li>
<li>Fix: Astaro Mail Gateway: Improved format detection, fixed negative size issue, and Index out of bounds errors.</li>
<li>Fix: IronPort WSA: Improved format detection.</li>
</ul>
<p><strong>How to update</strong></p>
<p>To update your software, simply click <strong>Tools | Check for updates</strong>. Vantage Ultimate users will also need to update the Web Module in order to use the new loader formats that have been added. To update the Vantage Web Module, right-click the WebSpy system tray icon and select ‘Check for updates’. If you have issues with the Web Module update process, please see: <a title="Web Module Update Issues" href="http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29</a></p>
<p>Let me know if you have any questions or issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How much do IronPort WSA Appliances eat?</title>
		<link>http://www.webspy.com.au/blogs/index.php/how-much-do-ironport-wsa-appliances-eat/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/how-much-do-ironport-wsa-appliances-eat/#comments</comments>
		<pubDate>Fri, 12 Nov 2010 05:32:47 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[Access Logs]]></category>
		<category><![CDATA[Cisco IronPort]]></category>
		<category><![CDATA[Disk]]></category>
		<category><![CDATA[HDD]]></category>
		<category><![CDATA[logging]]></category>
		<category><![CDATA[Requirements]]></category>
		<category><![CDATA[Size]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Web Security Appliances]]></category>
		<category><![CDATA[WebSpy Storage]]></category>
		<category><![CDATA[WSA]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2384</guid>
		<description><![CDATA[If you are thinking about deploying IronPort Web Security Appliances you probably want to plan how much disk space to budget for with regards to logging and reporting.
Every organization is different with regards to the volume of logs it creates, but I&#8217;ve averaged three data sets submitted to us by customers to produce the following [...]]]></description>
			<content:encoded><![CDATA[<p>If you are thinking about deploying IronPort Web Security Appliances you probably want to plan how much disk space to budget for with regards to logging and reporting.</p>
<p>Every organization is different with regards to the volume of logs it creates, but I&#8217;ve averaged three data sets submitted to us by customers to produce the following estimates.<span id="more-2384"></span></p>
<p>You will create roughly <strong>0.9 MB</strong> of IronPort WSA access logs per user per day.</p>
<p>Once imported into a WebSpy Storage, the Storage will be about<strong> 90%</strong> of your original log file size. If you apply NTFS compression to the storage folder, the actual size on disk of the WebSpy Storage will be about <strong>30%</strong> of your original log data.</p>
<p>So an organization with <strong>1000 user</strong>s will produce about <strong>900 MBs</strong> of access logs per day. The default WebSpy Storage  will be <strong>810 MB,</strong> but with NTFS compression, the size on disk will around <strong>270 MB</strong>.</p>
<p>As I said, this is a rough guide based on the average of three sets of sample logs we have in house, so please run your own tests and if you can, let us know your values in the comments below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/how-much-do-ironport-wsa-appliances-eat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.55 (Clearswift, Palo Alto Networks, WatchGuard and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 07:25:56 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[ClearSwift]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[FlowMonitor]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Partners]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[IOS Firewall]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Microsoft ISA]]></category>
		<category><![CDATA[PA Firewall]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[SECURE Web Gateway]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[Watchguard]]></category>
		<category><![CDATA[Web Security Appliance]]></category>
		<category><![CDATA[XTM]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2196</guid>
		<description><![CDATA[We&#8217;ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats.
What&#8217;s New?
Clearswift SECURE Web Gateway W3C
Clearswift have just released the latest version of their SECURE Web Gateway, which includes a transaction log export function. This enables you to send transaction logs [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats.<span id="more-2196"></span></p>
<h2>What&#8217;s New?</h2>
<h3>Clearswift SECURE Web Gateway W3C</h3>
<p>Clearswift have just released the latest version of their SECURE Web Gateway, which includes a transaction log export function. This enables you to send transaction logs in W3C format to an off-box FTP server for analysis. If you are updating to the latest Clearswift SECURE Web Gateway, make sure you update your Vantage software to 2.2.0.55 in order to import your W3C Transaction logs. <a title="Using WebSpy Vantage with ClearSwift SECURE Web Gateway" href="http://www.webspy.com/vendors/clearswift/howto.aspx" target="_blank">More information on using WebSpy Vantage with Clearswift SECURE Web Gateway</a>.</p>
<h3>Cisco Firewall Bandwidth loader</h3>
<p>We have also introduced a new Loader for Cisco ASA, PIX and IOS Firewall devices. This new loader imports TCP, UDP, ICMP and GRE &#8217;session close&#8217; events into one schema, allowing you to aggregate size values across these  events. This loader is called Cisco Firewall (Bandwidth) and is now available on the Loader Selection page of the Import Wizard. Previously, these events were imported into separate schemas so there was no great way to determine total bandwidth from your Cisco syslog files (<a title="How to report on bandwidth utilization using Netflow and WebSpy FlowMonitor" href="http://www.webspy.com.au/blogs/index.php/how-to-report-on-bandwidth-utilization-using-cisco-devices/" target="_blank">without using Netflow and WebSpy FlowMonitor</a>).</p>
<h3>Palo Alto Networks and WatchGuard XTM</h3>
<p>We&#8217;re also very happy to welcome Palo Alto Networks to the WebSpy supported log file list. Vantage now supports both the CSV and syslog file formats from your PA Firewall.</p>
<p>Another new addition is support for the latest WatchGuard XTM devices running firmware version 11.</p>
<h2>Full List of Changes</h2>
<p>Here&#8217;s the full list of changes included in this update:</p>
<ul>
<li>New: Clearswift SECURE Web Gateway W3C.</li>
<li>New: Palo Alto Networks Firewall (CSV/Syslog)</li>
<li>New: Cisco Firewall (Bandwidth): This new Cisco loader imports TCP, UDP, ICMP and GRE events from ASA, PIX and IOS syslogs into one schema to aggregate size values across these events.</li>
<li>New: Added WatchGuard XTM: Currently http-proxy, https-proxy, smtp-proxy and firewall lines are supported.</li>
<li>Fixed: ISA Server: Fixed format detection issues, and issues importing hits with very large size values.</li>
<li>Fixed: IronPort WSA: Fixed format detection issues, as well as the import issue &#8220;Invalid value for DVS Scan Code&#8221;</li>
<li>Fixed: Sophos WSA: Fixed format detection issues and invalid line issues.</li>
</ul>
<h2>How to update</h2>
<p>To update your software, simply click <strong>Tools | Check for updates</strong>. To update the Vantage Web Module, right-click the WebSpy system tray icon and select &#8216;Check for updates&#8217;. If you have issues with the Web Module update process, please see: <a title="Web Module Update Issues" href="http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29</a></p>
<p>Let me know if you have any questions or issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Advantages of using WebSpy with Cisco IronPort &#8211; New Video</title>
		<link>http://www.webspy.com.au/blogs/index.php/advantages-of-using-webspy-with-cisco-ironport-new-video/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/advantages-of-using-webspy-with-cisco-ironport-new-video/#comments</comments>
		<pubDate>Thu, 02 Sep 2010 05:55:08 +0000</pubDate>
		<dc:creator>Asa</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ironport channel]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[secure distribution]]></category>
		<category><![CDATA[Vantage Ultimate]]></category>
		<category><![CDATA[Web Module]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2109</guid>
		<description><![CDATA[WebSpy has been working closely with Cisco and the IronPort team over the past few years to develop what we believe is the most intuitive, flexible and fastest reporting solution for Cisco IronPort users.   
We’ve just completed our ‘WebSpy Reporting for Cisco IronPort’ video. Although this video is aimed at the Cisco channel [...]]]></description>
			<content:encoded><![CDATA[<p>WebSpy has been working closely with <strong>Cisco</strong> and the <strong>IronPort team</strong> over the past few years to develop what we believe is the most <strong>intuitive, flexible and fastest reporting solution for Cisco IronPort users.</strong>   </p>
<p>We’ve just completed our ‘WebSpy Reporting for Cisco IronPort’ video. Although this video is aimed at the Cisco channel we’d thought we share it with the rest of the WebSpy community as it provides a great high level overview of Vantage Ultimate’s ability to, not only import and spit out reports, but to learn about an organization’s structure in order to securely deliver the right report to the right person at the right time. </p>
<p><span id="more-2109"></span></p>
<p>Vantage Ultimate is structured in two parts. One <strong>windows application</strong>, that handles administration of importing log files, learning about your organizational structure, creating and running reports, and one <strong>web application</strong> (aka the web module) where users can securely log in to view the report that has been produced for them.  </p>
<p>Have a look at the short video below to find out what WebSpy&#8217;s founder, Jack Andrys, and product operations manager, Scott Glew, have to say about WebSpy&#8217;s and IronPort&#8217;s compatibility, as well as a demo of Vantage Ultimate in action. </p>
<p>&nbsp;</p>
<p><embed src="http://blip.tv/play/hLYlgfnHGQA" type="application/x-shockwave-flash" width="626" height="382" allowscriptaccess="always" allowfullscreen="true"></embed></p>
<p>&nbsp;</p>
<p>What&#8217;s the point with secure and easy report distribution you might ask? Well, among other things:</p>
<h2>Distribute Information. Distribute Responsibility.</h2>
<p>IT Managers are too often left with the responsibility of managing and enforcing acceptable Internet usage for the entire organization.</p>
<p>Using Vantage Ultimate administrators can distribute reports to managers or department heads that show the activity of their direct subordinates, placing the responsibility of enforcing acceptable usage with the managers themselves. </p>
<h2>Empower Users. Full Disclosure.</h2>
<p>You can use Vantage Ultimate to distribute reports to each member in your organization detailing their own personal Internet usage (sites visited, search terms used etc). This empowers users to modify their own behavior once they understand how much of their activity is productive or unproductive and what it costs the organization. It also serves as a gentle reminder to employees that their activities are being recorded and that they should keep their online behavior within the bounds of the organization’s acceptable use policy. </p>
<p>From a privacy point of view, Vantage Ultimate is an easy way to provide employees with full disclosure regarding the information recorded about them.</p>
<h2>Self Serve, On-Demand Investigation.</h2>
<p>You can also use Vantage Ultimate to distribute original data storages to any of your organization’s members, enabling them to conduct their own ad-hoc drilldowns on any information they require. For example, distribute storages to HR managers enabling them to investigate the activity of employees that have handed in their resignation notice, but still have access to confidential company resources.</p>
<h2>Protect Employee Privacy.</h2>
<p>By assigning permissions to each of your Vantage Ultimate users, you can ensure they can only view the reports they are allowed to view. However, some employees need to view the traffic of all users, but do not necessarily need to identify users. For example, a network administrator may need to view the amount of traffic downloaded from a particular site per user, but does not need to know which users where involved. </p>
<p>This is easily achieved using the ‘Identify users’ permission, which masks all usernames with a hash code. </p>
<p>&nbsp;</p>
<p>For more information about WebSpy’s compatibility with Cisco IronPort and free 30 day trials, visit <a href="www.webspy.com/ironport">www.webspy.com/ironport</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/advantages-of-using-webspy-with-cisco-ironport-new-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.50 (Juniper SA, Forefront Protection and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-50/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-50/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 05:43:03 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Avencis]]></category>
		<category><![CDATA[Forefront Protection for Exchange]]></category>
		<category><![CDATA[IAS Radius]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Loader]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2070</guid>
		<description><![CDATA[We have just released an auto update for the Vantage range of applications. This update includes support for the Juniper SA series and Microsoft Forefront Protection for Exchange 2010.
Here&#8217;s the full list of changes:

 New: Juniper SA Series. Vantage can import and report on web traffic and VPN connections.
 New: Microsoft Forefront Protection for Exchange [...]]]></description>
			<content:encoded><![CDATA[<p>We have just released an auto update for the Vantage range of applications. This update includes support for the Juniper SA series and Microsoft Forefront Protection for Exchange 2010.</p>
<p>Here&#8217;s the full list of changes:</p>
<ul>
<li> New: Juniper SA Series. Vantage can import and report on web traffic and VPN connections.</li>
<li> New: Microsoft Forefront Protection for Exchange 2010 format.</li>
<li> New: Avencis SSOx.</li>
<li> Improved: IronPort WSA: Department and Message fields were sometimes returned as null. Fixed.</li>
<li> Improved: Microsoft FTMG: Removed usage of deprecated &#8220;FilterInfo&#8221; field from W3C Web format.</li>
<li> Improved: Microsoft IAS Radius: Added support for Source/Destination IP and port (field code 5000).</li>
</ul>
<p><span id="more-2070"></span>To update your Vantage application simply select <strong>Tools | Check for updates</strong>. </p>
<p>To update the Vantage Web Module, right-click the WebSpy icon in the Web Module server&#8217;s system tray, and select <strong>Check for updates</strong>. If you have any issues with the Web Module update process, please see my previous blog regarding <a title="Web Module Errors and Workarounds" href="http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/" target="_blank">Web Module Errors and Workarounds</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-50/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website Categorization &#8211; Assessing Productivity</title>
		<link>http://www.webspy.com.au/blogs/index.php/website-categorization-assessing-productivity/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/website-categorization-assessing-productivity/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 07:46:02 +0000</pubDate>
		<dc:creator>Asa</dc:creator>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Blue Coat]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[productivity]]></category>
		<category><![CDATA[security vendors]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[website categorization]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1777</guid>
		<description><![CDATA[Security and Threat Management solutions, such as Microsoft Forefront TMG, IronPort and Blue Coat, use predefined URL categorization to simplify blocking and filtering management. Different security vendors have different ways of categorizing websites but it generally involves referring to a gigantic, regularly updated database of millions of websites sorted into 50-100 relevant categories.
Majority of security [...]]]></description>
			<content:encoded><![CDATA[<p>Security and Threat Management solutions, such as <a href="http://www.webspy.com.au/vendors/microsoft-ftmg/default.aspx">Microsoft Forefront TMG</a>, <a href="http://www.webspy.com.au/vendors/ironport/default.aspx">IronPort</a> and Blue Coat, use predefined URL categorization to simplify blocking and filtering management. Different security vendors have different ways of categorizing websites but it generally involves referring to a gigantic, regularly updated database of millions of websites sorted into 50-100 relevant categories.</p>
<p>Majority of security vendors will give you a high level overview of the categories, such as Sports, Shopping, Online Community, Streaming Media, Employment and Gambling, but rarely provides intuitive ways to further investigate the traffic going to the sites within these categories. The nifty thing about WebSpy&#8217;s solutions is that, as long as categories are logged, you can use WebSpy to analyze web browsing in relation to these categories and get a much clearer overview of your organization&#8217;s web usage.</p>
<p><span id="more-1777"></span></p>
<h2>Classify Productive &#038; Unproductive Categories</h2>
<p>Assessing productivity in relation to predefined categories is what I would like to focus on today. I have imported and run an analysis on <a href="http://www.webspy.com.au/vendors/microsoft-ftmg/default.aspx">TMG logs</a> using WebSpy Vantage. As previously mentioned, you can import logs from any security device <a href="http://www.webspy.com/resources/logformats.aspx">we support</a> &#8211; if the information is in the log file WebSpy can report on it. </p>
<p>TMG logs contain information whether traffic has been &#8216;Allowed&#8217;, &#8216;Denied&#8217; or &#8216;Failed&#8217;. Using WebSpy Vantage you can easily drill down further into this information. For example, let&#8217;s say I&#8217;m interested in having a look what categories have been allowed, i.e. not blocked, I simple expand the &#8216;Allowed&#8217; node and click &#8216;URL category&#8217;. </p>
<p><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/categories1.png" target="_blank"><div id="attachment_1812" class="wp-caption aligncenter" style="width: 310px"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/categories1-300x249.png" alt="" title="categories" width="300" height="249" class="size-medium wp-image-1812" /><p class="wp-caption-text">Allowed Categories - Click to Enlarge</p></div></a></p>
<p>This information is great but it doesn&#8217;t tell us anything about productivity. WebSpy Vantage not only provides this assessment for your entire organization, specific department and individual users, but also gives you the ability to customize the categories that are deemed productive as this can vary wildly depending on the industry and organization.</p>
<h2>How?</h2>
<p>You use WebSpy&#8217;s Aliases feature to sort categories in relation to your organization&#8217;s view of their productiveness. Our software comes with a default list of aliases so you can either edit these or set up new aliases. I&#8217;ll take you through the process of setting up an Alias from scratch. </p>
<h3>1. Creating a New Alias</h3>
<ul>
<li>
Click on the Alias tab and select &#8216;New Alias&#8217; in the top left corner</li>
<li>Name your Alias something appropriate and provide a short description. I&#8217;ll name mine &#8216;Productivity&#8217;.</li>
<li>Make sure &#8216;Apply alias to selected summaries&#8217; option is checked</li>
<li>Click &#8216;Schema&#8217; to specify the log file type and scroll down to the bottom of the list to locate and select &#8216;URL Category&#8217;.</li>
<li>Tick the &#8216;Group unresolved into a single name&#8217; box and name it something appropriate. Let&#8217;s go with &#8216;Uncertain&#8217;.</li>
<p>&nbsp;</p>
<p><a href="http://www.webspy.com.au/blogs/index.php/website-categorization-assessing-productivity/createalias/" rel="attachment wp-att-1826"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/createalias.png" alt="" title="createalias" width="492" height="690" class="aligncenter size-full wp-image-1826" /></a></p>
</ul>
<p>&nbsp;</p>
<h3>2. Add Alias Groups</h3>
<p>Once an alias has been added, you need to add alias groups. You can have as many alias groups as you want but for this purpose it makes sense to have only two, &#8216;Productive&#8217; and &#8216;Unproductive&#8217;. There might be certain categories, such as &#8216;Education/Reference&#8217; or &#8216;Blogs/Wiki&#8217;, that might be difficult to correctly deem as productive or unproductive and you&#8217;d rather not specify. If this is the case you don&#8217;t need to add an alias group as it will automatically be created for any category that hasn&#8217;t been grouped under the other alias groups. Remember how we ticket &#8216;Group unresolved into a single name&#8217; and called it &#8216;Uncertain&#8217; before. </p>
<ul>
<li>
Click the Add Group button in the Groups task pad.</li>
<li>Enter the desired alias group name (Productive) in the &#8216;Key&#8217; edit box and click OK. Repeat steps for the &#8216;Unproductive&#8217; group.</li>
<li>At this stage you could also add items (categories) to your group but I&#8217;m going to show you another way of adding categories.
<p>&nbsp;</p>
<p><a href="http://www.webspy.com.au/blogs/index.php/website-categorization-assessing-productivity/aliasgroup/" rel="attachment wp-att-1831"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/aliasgroup.png" alt="" title="aliasgroup" width="363" height="405" class="aligncenter size-full wp-image-1831" /></a></ul>
<p>&nbsp;</p>
<h3>3. Add Categories to your &#8216;Productive&#8217; and &#8216;Unproductive&#8217; Alias Groups</h3>
<p>This is where customization really works its charm. What is deemed as unproductive at one company might be completely legit and considered productive at another. For example, in a recruitment company one could assume it would perfectly normal for employees to visit other employment sites but this could be considered personal and unproductive at a hospital or real estate agent.</p>
<p><a href="http://www.webspy.com.au/blogs/index.php/website-categorization-assessing-productivity/unassigned/" rel="attachment wp-att-1836"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/unassigned.png" alt="" title="unassigned" width="197" height="274" class="alignright size-full wp-image-1836" /></a></p>
<p>&nbsp;</p>
<p>There&#8217;s a few different ways of adding items to an Alias group. While still in the Alias screen you can click &#8216;Refresh Unassigned&#8217; in the top right part of your screen. Because you haven&#8217;t assigned anything yet all categories will be displayed. From here you can simply highlight the category group, for example &#8216;Unproductive&#8217; and Ctrl + click all categories you want to place in that group. Once you&#8217;ve selected your categories right click and select &#8216;Add to selected group&#8217;. Repeat the process to add categories to your &#8216;Productive&#8217; group.</p>
<p>Alternatively, you can go back to the &#8216;URL Category&#8217; listings in the &#8216;Summaries&#8217; tab and Ctrl + click selected categories, right click and select &#8216;Add to alias&#8217;, select your &#8216;Productivity&#8217; alias from the drop down menu and select the &#8216;Productive&#8217; or &#8216;Unproductive&#8217; group.</p>
<h2>4. Assess Productivity</h2>
<p>With aliases, groups and items set up you&#8217;re ready to assess productive and unproductive browsing. In the &#8216;Summaries&#8217; screen, left hand side under &#8216;Aliases&#8217;, simple select your &#8216;Productivity&#8217; alias and the URL categories will be sorted in accordance with your view of their productiveness. </p>
<p>&nbsp;</p>
<p><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/unproductivevsproductive.png" target="_blank"><div id="attachment_1839" class="wp-caption aligncenter" style="width: 310px"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/unproductivevsproductive-300x228.png" alt="" title="unproductivevsproductive" width="300" height="228" class="size-medium wp-image-1839" /><p class="wp-caption-text">Productive vs Unproductive Browsing - Click to Enlarge</p></div></a></p>
<p>&nbsp;</p>
<p>You can also investigate further by, for example, drilling down to determine what unproductive categories are most popular, what are the most popular unproductive websites within those categories, what hours during the day majority of unproductive sites are accessed (you might have a policy that allows personal web browsing during lunch hours), and of course who spends the most time on unproductive websites within your organization.</p>
<p>&nbsp;</p>
<p><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/unproductivesites.png" target="_blank"><div id="attachment_1842" class="wp-caption aligncenter" style="width: 310px"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/07/unproductivesites-300x224.png" alt="" title="unproductivesites" width="300" height="224" class="size-medium wp-image-1842" /><p class="wp-caption-text">Top Unproductive Websites - Click to Enlarge</p></div></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/website-categorization-assessing-productivity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Video: How to use WebSpy Vantage to report on IronPort log files</title>
		<link>http://www.webspy.com.au/blogs/index.php/video-how-to-use-webspy-vantage-to-report-on-ironport-log-files/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/video-how-to-use-webspy-vantage-to-report-on-ironport-log-files/#comments</comments>
		<pubDate>Fri, 18 Jun 2010 02:01:16 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Aliases]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[dynamic reports]]></category>
		<category><![CDATA[Import]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[Organization]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1695</guid>
		<description><![CDATA[I&#8217;ve produced a video on how to use WebSpy Vantage to report on IronPort&#8217;s Web Security Appliance&#8217;s access log files. It is quite a detailed look at the key tasks involved in setting up and using WebSpy Vantage with IronPort WSA access logs, and is therefore divided into several parts. The videos take you through [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve produced a video on how to use WebSpy Vantage to report on IronPort&#8217;s Web Security Appliance&#8217;s access log files. It is quite a detailed look at the key tasks involved in setting up and using WebSpy Vantage with IronPort WSA access logs, and is therefore divided into several parts. The videos take you through the following activities:</p>
<ul>
<li>How to import your log files and explore the information recorded by IronPort using the Summaries screen</li>
<li>How to open the customized IronPort Report Templates and Aliases</li>
<li>How to generate reports</li>
<li>How to import your organizational structure and report on departments</li>
<li>How to setup the Web Module and publish reports</li>
</ul>
<h3><span id="more-1695"></span>PART 1: Importing log files &amp; exploring your IronPort summaries</h3>
<p>Once you have exported your IronPort access logs (see <a title="How to Import and Analyze IronPort log files" href="http://www.webspy.com.au/vendors/ironport/howto.aspx#ftp" target="_blank">http://www.webspy.com.au/vendors/ironport/howto.aspx#ftp</a>), this video takes you through importing your logs into WebSpy Vantage and analyzing data on the Summaries screen.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjMgA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjMgA" allowfullscreen="true"></embed></object></p>
<h3>PART 2: Opening the customized IronPort Templates &amp; Aliases, and running reports</h3>
<p>This video takes you through opening the IronPort-specific report templates and aliases and generating a report that provides an overview of your organization&#8217;s Internet usage.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjOAA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjOAA" allowfullscreen="true"></embed></object></p>
<h3>PART 3: Importing your Organization structure &amp; generating department reports</h3>
<p>This video shows you how to import your organizational structure into WebSpy Vantage from a directory server (such as Active Directory) using LDAP, and then generating a report that contains information on your newly imported departments.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjPAA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjPAA" allowfullscreen="true"></embed></object></p>
<h3>PART 4: Using the Web Module.</h3>
<p>This video takes you through configuring and using the WebSpy Vantage Web Module. Specifically, it takes you through the following tasks:</p>
<ul>
<li>Configuring the Web Module for Windows Authentication</li>
<li>Adding a Web Module to Vantage</li>
<li>Publishing reports to the Web Module</li>
<li>Adding permissions for a user</li>
<li>Synchronizing the Web Module</li>
<li>Using the Dynamic Reports tab</li>
</ul>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjSAA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjSAA" allowfullscreen="true"></embed></object></p>
<h3>PART 5: A quick word about tasks &amp; conclusion</h3>
<p>This video summarizes the actions taken in the previous four videos and also briefly discusses how to automate the reporting processing using scheduled tasks.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="255" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://blip.tv/play/hLYlgebjSwA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="255" src="http://blip.tv/play/hLYlgebjSwA" allowfullscreen="true"></embed></object></p>
<p>I hope this helps! Let me know if you have any questions by leaving a comment below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/video-how-to-use-webspy-vantage-to-report-on-ironport-log-files/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.43</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/#comments</comments>
		<pubDate>Thu, 20 May 2010 06:45:45 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Astaro]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[BlueCoat]]></category>
		<category><![CDATA[ClearSwift]]></category>
		<category><![CDATA[dynamic reports]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[microsoft Forefront TMG]]></category>
		<category><![CDATA[NetAsq]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1511</guid>
		<description><![CDATA[We've just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module. This is a great update for Vantage Ultimate users as we've introduced a new feature/tab into the Web Module called 'Dynamic Reports'.

Here's the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module.</p>
<p>This is a great update for Vantage Ultimate users as we&#8217;ve introduced a new feature/tab into the Web Module called &#8216;Dynamic Reports&#8217;.</p>
<p>If you&#8217;re publishing the same report to the Web Module each day, you can use the Dynamic Reports tab to select a date range and a department (or whatever organizational groups you have defined) and the Web Module will collate all the daily reports that match that filter into one report. This allows you to report on entire week, month or year by simply &#8216;reporting on reports&#8217;, rather than reporting months of raw storage data.</p>
<p>Here&#8217;s the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).</p>
<p><strong>Application Changes</strong></p>
<ul>
<li>Added Dynamic Reports feature to the Web Module.</li>
<li>Rewrote the Web Module transfer protocol. New protocol adds version checking, connection checking, and integrity checking for high latency environments.</li>
<li>Purge data from storage task no longer prevents importing new hits when all data is removed from an input within a storage.</li>
<li>IPv6 addresses now show IPv4-mapped addresses as plain IPv4 addresses in summaries.</li>
<li>IPv6 and IPv4 addresses are now freely interchangable in filter expressions.</li>
<li>Fixed IPv6 drilldowns on the Summaries screen</li>
<li>SQL inputs can now be resumed from the previous position. Previously any input that was partially imported would be skipped when importing new hits.</li>
<li>Template-based analysis has been fixed, no longer results in blank/non-existent analysis.</li>
<li>Added new string manipulation functions to expression language; Contains, StartsWith, EndsWith, IndexOf.</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>Astaro: Now checks that the ID field is present in a line before attempting to read it.</li>
<li>Barracuda Web Filter: Added this format to replace Spy Filter.</li>
<li>BlueCoat Proxy SG W3C: Added support for gmttime, timestamp, x-bluecoat-surfcontrol-is-denied and x-bluecoat-transaction-id.</li>
<li>ClearSwift: Added a new loader group for ClearSwift that includes the MimeSweeper loaders</li>
<li>ClearSwift SECURE Web Gatway: Now supported with the Web Appliance loader</li>
<li>Clearswift Web Appliance: User summary displays Source IP if Username is blank.</li>
<li>IronPort WSA: Fixed memory usage issues.</li>
<li>Microsoft FTMG: Added category name lookup to SQL loader.</li>
<li>Microsoft FTMG: No longer fails to import lines where the rule field contains square brackets.</li>
<li>Microsoft FTMG: URL Category field is now a string instead of an integer. Added URL Categorization Reason field.</li>
<li>Microsoft FTMG: Fixed memory usage issues.</li>
<li>Microsoft IIS W3C: No longer hangs or crashes when loading a file that isn&#8217;t IIS W3C.</li>
<li>NetAsq: Added support for srcname field. The Username summary is populated with user first, and then srcname if user is blank. The User summary is also now populated with Source IPs if the Username summary is blank.</li>
</ul>
<p>To update WebSpy Vantage, simple select Tools | Check for updates.</p>
<p>To update the Web Module, login to the Web Module server, right-click the WebSpy system tray icon, and select Check for updates.</p>
<p>As always, please <a title="Contact WebSpy" href="http://www.webspy.com/about/contact.aspx" target="_blank">contact us</a> if you have any issues or questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>3 Simple Reasons Why Resellers Want WebSpy</title>
		<link>http://www.webspy.com.au/blogs/index.php/3-simple-reasons-why-resellers-want-webspy/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/3-simple-reasons-why-resellers-want-webspy/#comments</comments>
		<pubDate>Fri, 16 Apr 2010 07:48:58 +0000</pubDate>
		<dc:creator>Asa</dc:creator>
				<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Partners]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Sales and Marketing]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Astaro]]></category>
		<category><![CDATA[Barracuda Networks]]></category>
		<category><![CDATA[Blue Coat]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[reporting problems]]></category>
		<category><![CDATA[resellers]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Squid Proxy]]></category>
		<category><![CDATA[TMG]]></category>
		<category><![CDATA[vendors]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1352</guid>
		<description><![CDATA[To set things straight from the get-go, this is not a plug about our partner program, margin structure or reseller support. All the ingredients necessary to bake a successful partner cake are present (and being improved&#8230;get ready for some exciting partner announcement in the coming weeks). No, this is simply a very factual overview of [...]]]></description>
			<content:encoded><![CDATA[<p>To set things straight from the get-go, this is not a plug about our partner program, margin structure or reseller support. All the ingredients necessary to bake a successful partner cake are present (and being improved&#8230;get ready for some exciting partner announcement in the coming weeks). No, this is simply a very factual overview of the Network and Security Industry, where majority of security vendors fall short and where WebSpy continues to save our resellers’ day.</p>
<p><span id="more-1352"></span></p>
<p>&nbsp;</p>
<h2>WebSpy’s Industry Fit</h2>
<p>WebSpy is a global leader in reporting and analysis on Internet activity when used in partnership with security vendors such as <strong>Microsoft ISA Server, Microsoft Forefront TMG, Cisco IronPort, Blue Coat, Sophos, Astaro, Barracuda, Squid Proxy</strong>, and <a href="http://www.webspy.com.au/resources/logformats.aspx">many more</a>. </p>
<p>Below image neatly summarizes how WebSpy report on log files from vendor devices in the Unified Threat Management (UTM) and Secure Web Gateway (SWG) sectors, and specifically focus on reporting and analysis on Internet activity aspects within the SIEM sector. </p>
<p><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2010/04/webspy-industry-fit.jpg" alt="webspy-industry-fit" title="webspy-industry-fit" width="545" height="393" class="aligncenter size-full wp-image-1353" /></p>
<h1>THE REASONS</h1>
<p>&nbsp;</p>
<h2><strong>1. WebSpy Adds Value to Existing Product Portfolio</strong></h2>
<p>There’s a multitude of reputable, solid and reliable security vendors that frequently form a part of our resellers’ product portfolio. Their network and security devices do a great job providing network structure and actively protecting against security issues.  </p>
<p>However, analysis and reporting is not their forte, not their core, and more often than not reporting is only a feature within their complete network and security solution.</p>
<p><a href="http://en.wikipedia.org/wiki/Magic_Quadrant">Gartner’s latest Magic Quadrants</a> on SWG and UTM vendors (or “SMB Multifunctional Firewalls” as labelled by Gartner) clearly highlights the security vendor’s weakness in reporting. </p>
<p>Straight from the horse’s mouth, here’s some vendor reporting issues as highlighted by Gartner:</p>
<ul>
<li>“Lacking enterprise-class administration and reporting capabilities.”</li>
<li>“Advanced ad-hoc reporting features are lacking and custom reports are limited to filter settings on existing reports.”</li>
<li>“Reports are very basic, and there are only a limited number of pre-developed reports.”</li>
<li>“Per-user reports and forensic investigations are weak.”</li>
<li>“On-box reporting is very basic and requires Windows and SQL database licenses for the reporting server.”</li>
<li>“The number of canned reports is low and some reports do not have obvious features, such as pie graph options. Some customers complained about the scalability of the reporting interface.”</li>
<li>“Users describe the vendor’s reporting and alerting as difficult to use.”</li>
<li>“Although management is strong, users cite quality of reporting as a deficiency.”</li>
</ul>
<p>With this information at hand it comes as no surprise that resellers want WebSpy’s reporting solutions to complement and add value to existing Internet security devices and provide their clients with valuable, advanced, customized and scalable reports on the exact use of web servers, web proxy, servers, email server, firewalls, switches, routers, and spam and virus application.</p>
<p>&nbsp;</p>
<h2><strong>2. WebSpy Helps Generate and Facilitate SWG and UTM sales opportunities</strong></h2>
<p>You’ll be surprised by the amount of clients who base the decision of which Internet security device to purchase on reporting abilities.</p>
<p>WebSpy has a proven track record of assisting both Internet security vendors, such as IronPort, Microsoft ISA Server, Sophos, and their resellers in securing sales of their Internet security appliances. On numerous occasions our resellers have been able to secure deals, which could have been lost to a competing vendor/reseller, simply because they were able to throw advanced reporting into the mix.</p>
<p>&nbsp;</p>
<h2><strong>3. WebSpy Substantially Increase Sales Revenue through Add-On Sales</strong></h2>
<p>Our resellers have found that recommending WebSpy reporting with every Internet security and network installation gives them the ability substantially increase add-on sales revenue with limited efforts involved. </p>
<p>The fact we offer competitive upgrade rebates if a reseller’s client have already invested time and money in a competing third-party reporting solution, or on-appliance reporting, naturally makes the transition to WebSpy even smoother.</p>
<p>&nbsp;</p>
<p><strong>Not convinced? Have a look at these:</strong></p>
<ul>
<li><a href="http://www.webspy.com.au/isaserver/webspy-and-isa.aspx">10 Reasons to report on ISA Server using WebSpy </a></li>
<li><a href="http://www.webspy.com/vendors/ironport/">10 Reasons to report on IronPort using WebSpy</a></li>
<li><a href="http://www.webspy.com/vendors/sophos/default.aspx">10 Reasons to report on Sophos using WebSpy</a></li>
<li><a href="http://www.webspy.com.au/blogs/index.php/8-reasons-not-to-use-microsoft-forefront-tmgs-reporting/">8 Reasons NOT to Use Microsoft Forefront TMG’s Reporting</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/3-simple-reasons-why-resellers-want-webspy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.29 &#8211; New Fields for IronPort</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 06:55:01 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[bytes received]]></category>
		<category><![CDATA[bytes sent]]></category>
		<category><![CDATA[fields]]></category>
		<category><![CDATA[group]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[WebSpy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1282</guid>
		<description><![CDATA[We have just added support for the 'Group' field in IronPort's access logs. You can add this field to your logs by adding %g in the 'Custom Fields' edit box. We have also added support for the custom fields Body Request Size and Body Response Size.]]></description>
			<content:encoded><![CDATA[<p>We have just added support for the &#8216;Group&#8217; field in IronPort&#8217;s access logs. You can add this field to your logs by adding %g in the &#8216;Custom Fields&#8217; edit box (on your IronPort WSA appliance  under System Administration | Log Subscriptions | accesslogs).</p>
<p>When imported into WebSpy Vantage, the result is shown in a new summary called &#8216;Group&#8217; which you can add to your reports.<span id="more-1282"></span></p>
<p><del datetime="2010-03-16T01:30:47+00:00">We also added support for the custom fields Bytes Sent and Bytes Received. Due to the absence of a header in the IronPort access log, Bytes Received and Bytes Sent fields must both be present to be detected, and the Received field must precede the Sent field.</del></p>
<p>We also added support for the custom fields Request Body Size and Response Body Size. These fields can be included in your access log by adding %q (Request body size) and %b (Response body size)  in the &#8216;Custom Fields&#8217; edit box. Due to the absence of a header in the IronPort access log, Request Body Size and Response Body Size fields must both be present to be detected, and the Request field must precede the Response field.</p>
<p><del datetime="2010-03-16T01:30:47+00:00">We&#8217;ve also noticed that the values in the Bytes Sent and Bytes Received fields do not necessarily add up to the value logged for &#8216;Size&#8217;. We&#8217;re discussing this issue with our friends at IronPort and we will hopefully post a solution or explanation soon.</del>.<br />
The information we first received about these fields indicated they represented Bytes Sent and Bytes Received. This is the way they are represented in the builds below (2.2.0.29). We will release a new build soon, with the field names changed to Request body size and Response body size. Body size is different to bytes sent/received as it does not include bytes from packet headers etc.</p>
<p>We&#8217;re yet to issue an automatic update for the Vantage applications, so in the mean time you can download the latest builds here:</p>
<p>Vantage Ultimate:<br />
<a title="Vantage Ultimate 2.2.0.29" href="ftp://ftp.webspy.com/webspy/Builds/VantageUltimate2.2.0.29.zip" target="_blank"> ftp://ftp.webspy.com/webspy/Builds/VantageUltimate2.2.0.29.zip</a></p>
<p>Vantage Web Module:<br />
<a href="ftp://ftp.webspy.com/webspy/Builds/VantageWebModule2.2.0.8.exe">ftp://ftp.webspy.com/webspy/Builds/VantageWebModule2.2.0.8.exe</a></p>
<p>Vantage Giga:<br />
<a title="Vantage Giga 2.2.0.27" href="ftp://ftp.webspy.com/webspy/Builds/VantageGiga2.2.0.29.zip" target="_blank">ftp://ftp.webspy.com/webspy/Builds/VantageGiga2.2.0.29.zip</a></p>
<p>Vantage Premium:<br />
<a title="Vantage Premium 2.2.0.29" href="ftp://ftp.webspy.com/webspy/Builds/VantagePremium.2.0.29.zip" target="_blank">ftp://ftp.webspy.com/webspy/Builds/VantagePremium2.2.0.29.zip</a></p>
<p><strong>To apply the Vantage update</strong>, close Vantage and extract the downloaded file into Vantage’s installation folder (Usually c:\Program Files\WebSpy\Vantage &lt;flavour&gt; 2.2). Overwrite the existing files.</p>
<p><strong>To apply the Web Module update</strong>, uninstall the Vantage Web Module from Add/Remove Programs (Programs and Features in Windows 7/Server 2008), then run the downloaded exe file, making sure you specify the same server, virtual directory and data location that your Web Module was previously using.</p>
<p>We will be releasing this as a public auto-update soon. Let us know if you have any issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Universal Log File Analyzer</title>
		<link>http://www.webspy.com.au/blogs/index.php/universal-log-file-analyzer/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/universal-log-file-analyzer/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 10:01:53 +0000</pubDate>
		<dc:creator>Asa</dc:creator>
				<category><![CDATA[Sales and Marketing]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Blue Coat]]></category>
		<category><![CDATA[CHeckPoint]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[log file]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Squid]]></category>
		<category><![CDATA[supported log file formats]]></category>
		<category><![CDATA[Universal Log analyzer]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1065</guid>
		<description><![CDATA[WebSpy analyze and report on different types of log files, from different types of network and security devices (such as web servers, web proxy servers, email server, event logs, firewalls, switches, routers, and spam and virus application), taking raw data and converting it into meaningful and  actionable information.
We take great pride in this versatility [...]]]></description>
			<content:encoded><![CDATA[<p>WebSpy analyze and report on different types of log files, from different types of network and security devices (such as web servers, web proxy servers, email server, event logs, firewalls, switches, routers, and spam and virus application), taking raw data and converting it into meaningful and  actionable information.</p>
<p>We take great pride in this versatility and the fact that our software is virtually vendor neutral, or universal. At the time of writing our software support 128 different vendors, and more than 250 log file formats. But what does all this actually mean?  What’s all this log file format gibberish and why is better to use a universal log file analyzer than a reporting solution that can only analyze a limited set of log files?</p>
<p><span id="more-1065"></span></p>
<p>Let’s break it down&#8230;</p>
<h2>What is a Log File?</h2>
<p>A log file is a set of data that is automatically created and maintained by a security or network device of activity performed by it.</p>
<p>Web proxy servers maintain log files listing details on every request, from outgoing traffic, made to the proxy server &#8211; who is accessing external sites, what sites are being accessed, when the sites were accessed, what page or search phrase referred the user to the sites, and the type and size of data downloaded from the sites. Email servers store log files containing data about the sender, the receiver, timing of delivery or receipt, subject line, and size of attachment. Firewalls, and other security devices, normally contain data about network activity and the external and internal traffic that has been blocked or filtered.</p>
<p>Log files contains bundles of information and are usually not very structured or easy to decipher. Here’s what a  log file can look like:</p>
<div id="attachment_1067" class="wp-caption aligncenter" style="width: 304px"><img class="size-full wp-image-1067 " title="logfile" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/12/logfile.jpg" alt="logfile" width="294" height="184" /><p class="wp-caption-text">Can you see the need for a log file analyzer?</p></div>
<h2>Who are the Network and Security Device Vendors?</h2>
<p>There’s a bunch of them to say the least. A recent WebSpy customer survey showed that Microsoft, Novell, Squid, IronPort, Blue Coat and CheckPoint were the top vendors whose products our clients wanted to analyze.</p>
<p>Checkout the whole list (128) of vendors we support at <a href="http://www.webspy.com.au/resources/logformats.aspx ">http://www.webspy.com.au/resources/logformats.aspx </a></p>
<h2>What is a Log File Format?</h2>
<p>When we state we can analyze more than 250 different log file formats we take into account the different log files formats produced depending on the vendors&#8217; product, product version and log type</p>
<p>For example: Microsoft develops products such as Exchange, IIS, Proxy Server and ISA Server. ISA Server comes in different versions (2000, 2004 and 2006). Each version can log and store different types of log files (file, MSDE Database and SQL Database). So, ISA Server MSDE Database 2004 is one log file format we support, ISA Server file 2000 is another.</p>
<h2>Benefits of a Universal Log Analyzer</h2>
<p>The 250 something log file formats WebSpy analyze and report on are simply the most common ones. It is very rare that we come across a client who need to analyze a log file that is not already on our list of supported log files. On the odd occasion this does occur, the client can simply request support for their specific log file format, our developers work their magic and wham – we support one more log file format.</p>
<p>Most competing log file analyzers are hard-coded to analyze a particular log file type. When this is the case their clients will need a different log analyzer to achieve each individual reporting requirement, increasing the time and costs involved to produce all the required reports.</p>
<p>WebSpy’s clients, on the other hand, reap the rewards of using one application to achieve all their reporting requirements, spending less on software maintenance, hardware and administration.<!--more--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/universal-log-file-analyzer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exciting New Features in Vantage Update 2.2.0.10</title>
		<link>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 07:27:29 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Bug Fixes]]></category>
		<category><![CDATA[CSV]]></category>
		<category><![CDATA[Data Purge]]></category>
		<category><![CDATA[ExoServer]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Import Organization]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[New Features]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Tasks]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=593</guid>
		<description><![CDATA[Attention all Vantage customers (and triallers). We've just released build 2.2.0.8 as an auto-update. This build includes new features such as scheduled data purge, support for Microsoft Forefront Threat Management Gateway, and scheduling CSV imports into your Organizational structure.]]></description>
			<content:encoded><![CDATA[<p>Attention all Vantage customers (and evaluators). We&#8217;ve just released build 2.2.0.10 as an auto-update. This build includes support for Microsoft Forefront Threat Management Gateway, and new features such as scheduled &#8216;data purge&#8217; and scheduling CSV imports into your Organizational structure.</p>
<p><span id="more-593"></span></p>
<p>You should be prompted to update your software on startup, but if you&#8217;ve turned off that feature, simply go to <strong>Tools | Check for Updates</strong>.</p>
<h2>New Features</h2>
<p>This new build sports the following new features:</p>
<ul>
<li> <strong>Support for Microsoft Forefront Threat Management Gateway (Beta)</strong><br />Microsoft Forefront Threat Management Gateway (FTMG) is still currently in Beta, and is due to be released around November 2009. For those that do not know, FTMG is the next version of Microsoft&#8217;s popular ISA Server. Information and downloads for FTMG can be found here <a href="http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/tmg-beta.aspx">http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/tmg-beta.aspx</a>. We have added support for FTMG beta 2 and 3 for both the W3C text logs (recommended) and the internal SQL Server Express Database logs. If you are currently trialling FTMG, we are very interested to hear your feedback. Let us know how you go!
<div id="attachment_596" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg.png"><img class="size-medium wp-image-596 " title="Now Supported - Microsoft Forefront Threat Management Gateway" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg-300x225.png" alt="Microsoft Forefront Threat Management Gateway" width="300" height="225" /></a><p class="wp-caption-text">Now Supported - Microsoft Forefront Threat Management Gateway</p></div></li>
<li><span style="background-color: #ffffff;"><strong>Data purge</strong><br />
You can now purge data from a storage, and schedule this purge to occur on a regular basis using Tasks. Purge options include data between a date range, data before a date, data after a date, data older than a date relative to now, and all data. This feature will let you easily maintain a single storage that only includes data for the last month or day.</p>
<p><div id="attachment_594" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/purge-storage.png"><img class="size-medium wp-image-594" title="Purge Storage Wizard" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/purge-storage-300x225.png" alt="Options for Purging data from your storage" width="300" height="225" /></a><p class="wp-caption-text">Options for Purging data from your storage</p></div>
<p></span></li>
<li><strong>Import Organization from CSV can now be scheduled using Tasks</strong><br />
<span style="font-weight: normal;"><span style="background-color: #ffffff;">If you are importing your organizational structure from CSV, you can now schedule this action using Tasks. This enables you to update your organizational structure before any reports are run.</span></span></p>
<p><div id="attachment_597" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-from-csv.png"><img class="size-medium wp-image-597" title="Import Organization from CSV via Tasks" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-from-csv-300x224.png" alt="Import Organization from CSV via Tasks" width="300" height="224" /></a><p class="wp-caption-text">Import Organization from CSV via Tasks</p></div></li>
<li> <strong><span style="background-color: #ffffff;">Added Support for ExoServer Web</span></strong><br />
If you&#8217;re running ExoServer Web, you can now analyze it&#8217;s logs using WebSpy Vantage.</li>
</ul>
<h2>Fixes</h2>
<p>We also fixed some things that may have been bugging you:</p>
<ul>
<li><span style="background-color: #ffffff;">Improved the start time for the application by improving the logic to check for Storage damage.</span></li>
<li><span style="background-color: #ffffff;">Fixed the IronPort loader (Fixed out of range issues on excessive size fields).</span></li>
<li><span style="background-color: #ffffff;">&#8220;Having&#8221; filters no longer override the sort order of a Report Template node.</span></li>
<li><span style="background-color: #ffffff;">Fixed an issue that may result in duplicated storages after migrating settings from earlier versions.</span></li>
<li><span style="background-color: #ffffff;">Fixed the inability to remove invalid entities from web module permissions list (users that no longer exist).</span></li>
<li>Fixed a timeout issue when publishing storages to the web module.</li>
</ul>
<p>Why are you still reading? Go update now!</p>
<p>Have fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebSpy User Survey &#8211; The Why, How and What Behind Internet Monitoring</title>
		<link>http://www.webspy.com.au/blogs/index.php/webspy-user-survey/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/webspy-user-survey/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 03:10:33 +0000</pubDate>
		<dc:creator>Asa</dc:creator>
				<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Sales and Marketing]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[business issues]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[monitoring log files]]></category>
		<category><![CDATA[Multi-processing]]></category>
		<category><![CDATA[Multi-threading]]></category>
		<category><![CDATA[software features]]></category>
		<category><![CDATA[Squid Proxy Server]]></category>
		<category><![CDATA[suggested improvements]]></category>
		<category><![CDATA[survey]]></category>
		<category><![CDATA[Windows Event Logs]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=490</guid>
		<description><![CDATA[We recently completed the analysis of our latest software user survey. It is always very exciting to review the results from such a survey since it is one of the best indications on why clients are using our software, where our strengths lies and what we can improve.

I would like to take this opportunity to [...]]]></description>
			<content:encoded><![CDATA[<p>We recently completed the analysis of our latest software user survey. It is always very exciting to review the results from such a survey since it is one of the best indications on why clients are using our software, where our strengths lies and what we can improve.<br />
<span id="more-490"></span><br />
I would like to take this opportunity to thank all of our clients who participated in the survey. Many of you wrote lengthy answers to each question making it very easy for us to understand why and how you use our software, what features you find valuable and what improvements, or added features, you would like to see. </p>
<p>The survey only consisted of six questions and to prevent influencing answers and encouraging unique thoughts and opinions, the majority of questions were open ended. Those answers applicable for categorization have now been categorized, compared and correlated. The survey was conducted for internal purposes but I would like to share some of the findings and comments we received. </p>
<h2>Vendor devices and log formats</h2>
<p>The top ten vendor devices client used WebSpy’s software to analyze and report on:</p>
<ol>
<li>Microsoft ISA Server (a whopping 48.6%)</li>
<li>Microsoft Exchange</li>
<li>Novell – BorderManager</li>
<li>Squid – Proxy Server</li>
<li>Microsoft Proxy Server</li>
<li>Microsoft  &#8211; Internet Information Services (IIS)</li>
<li>Blue Coat – Proxy SG</li>
<li>Check Point – Next Generation</li>
<li>IronPort – Web Security Appliance</li>
<li>Microsoft – Windows Event Logs</li>
</ol>
<h2>Business Issues</h2>
<p>The most common reason why clients started to monitor and report on their log files:</p>
<ol>
<li>To achieve transparency, higher visibility, on overall internet and network resources. (No actual issue quoted)</li>
<li>To reduce issues related to lost productivity, inappropriate and illegal internet usage</li>
<li>To be able to perform detailed investigations on specific user and site levels</li>
<li>To reduce bandwidth cost and increase speed</li>
<li>To achieve monitoring requirements not satisfied by vendor device</li>
<li>To reduce viruses and other security issues</li>
<li>To produce reports required by management</li>
<li>To trend and forecast Internet and network usage</li>
<li>To investigate email usage</li>
<li>To immediately address critical issues using real-time monitoring and alerts</li>
</ol>
<h2>Most valued WebSpy software features</h2>
<ol>
<li>Dynamic Drilldowns</li>
<li>Ad-hoc analysis and summaries screen</li>
<li>Real-time monitoring and alerts</li>
<li>Comprehensive and detailed reports and analysis options</li>
<li>Predefined and customizable reporting and analysis templates</li>
<li>Aliases – Logical grouping of data to represent it more meaningfully</li>
<li>Profiles &#8211; Categorize web site URLs, email subject lines, instant message chats and any other logged data using customizable keyword profiling technology.</li>
<li>Extensive log file compatibility and support</li>
<li>Ease of use</li>
<li>Automated task scheduling</li>
</ol>
<h2>Suggested Improvements</h2>
<p>The majority of answers related to suggested improvements and added software features were very specific to individual user experiences and quite difficult to categorize.  However, here a list of suggested improvements that our development has taken to heart and decided to prioritize:<br />
<strong><br />
Increase and Improve Number of Default Report and Analysis Templates</strong><br />
Major changes and improvements to our reporting engine and interfaces are currently being planned. A short term goal is to provide the ability to create reports in PDF format. This should hopefully be available in the coming months. </p>
<p>Longer term, we will be incorporating a visual report designer (drag / drop charts and tables etc), as well as the ability to create reports that collate information from different sources. For example, using the information from Event logs, Web proxy logs and email server logs, you could produce a report that shows when a user logged on to their PC, what sites they browsed, what files they accessed, and the emails they sent – all sorted chronologically in the one table!  </p>
<p>We currently have a large range of report templates available, but choosing the one you want can be a time consuming process, and you will most likely want to customize the report once you’ve found one that suits. We are planning to make the whole process of creating the report YOU want much, much easier.</p>
<p><strong>Further Expand Profiles (Website Categorization)</strong><br />
When it comes to website categorization, WebSpy applications utilize keyword profiling in addition to importing category fields from log files (if available). There are upsides and downsides to keyword profiling. A simple keyword can instantly categorize thousands of sites which is much more efficient than maintaining a URL Category database. Being able to categorizing hits to your own organization’s website or intranet is also a very useful feature. </p>
<p>We are committed to distributing more frequent profile updates, without overwriting any customizations you have made. Longer term, we plan to provide an option for collaborative keyword customization, so that you benefit from the customization that other customers are making around the world.  We also plan to integrate third party categorization services, as there are many great organizations that focus purely on URL categorization. </p>
<p><strong>Improve Software Updates Correspondence  </strong><br />
Our main mass communication channels include our newsletter, press releases blog and twitter. Here is where we inform existing and prospective clients about our software, updates, offers and much more. Starting September 2009 we will also send out emails, on a monthly basis, informing existing clients about the specific software updates implemented and are ready to download. </p>
<p><strong>Further Improve Reporting Speed</strong><br />
Vantage 2.2 ranges (Premium, Giga and Ultimate) now use multithreading techniques to utilize the extra processing power on machines with multiple cores or CPUs to import log files and generate reports faster. In addition to the multi-processing improvements recently made in Vantage 2.2, the development team are planning to implement even more multi threading improvements in the next major version. These improvements will be available for users of both the Analyzer and Vantage range.  </p>
<p>Thanks again for your participation!</p>
<p><em>The winner of the USB Camera Pen has been picked using a random draw and will be contacted personally via email.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/webspy-user-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

