<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebSpy Blog&#187; Loaders &#8211; WebSpy Blog</title>
	<atom:link href="http://www.webspy.com.au/blogs/index.php/tag/loaders/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.webspy.com.au/blogs</link>
	<description>For when WebSpyrians have something to say.</description>
	<lastBuildDate>Fri, 09 Dec 2011 01:18:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Vantage Update 2.2.0.68 (Exchange 2010, Juniper and IronPort Traffic Logs, and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 02:18:27 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Exchange]]></category>
		<category><![CDATA[fixes]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[Squid]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2494</guid>
		<description><![CDATA[We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.
Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as [...]]]></description>
			<content:encoded><![CDATA[<p>We have released an automatic update for the Vantage range of applications. This update includes some new loader formats, an experimental feature as well minor fixes and improvements.</p>
<p>Of note, this release includes full support for Microsoft Exchange 2010 Tracking logs (previously supported with the Exchange 2007 loader, but missing a few fields), as well as JunOS (Juniper) Traffic Logs, IronPort Traffic Monitor Logs and Squid Syslog.<span id="more-2494"></span></p>
<p>We&#8217;ve also included an experimental feature to allow multiple instances of WebSpy Vantage to run on the same operating system. The goal here is to run multiple reports at the same time using multiple instances of the application. To do this, we have also included a second experimental feature to disable storage locking. This allows multiple instances of Vantage to read from the same storage at once. These features can only be enabled by including a config file next to the Vantage&#8217;s executable. <a title="Running Multiple=">More on this feature here</a>.</p>
<p>Here&#8217;s the full list of changes:</p>
<h3>Application Changes</h3>
<ul>
<li>New: Added suffix option to Import Windows Users wizard in Aliases.</li>
<li>New: Date modifiers now supports h for hour and n for minute, e.g. %[-2h,yyyyMM - HH].</li>
<li>New: Added tracing to storage publish task.</li>
<li>Experimental: Multiple instances of Vantage can now be run simultaneously, by adding the multipleInstance key to the application config file.</li>
<li>Experimental: Storage locking can be turned off to allow multiple instances of Vantage to run reports on a single storage simultaneously. This is done by adding the storageLocking key to the application config file.</li>
<li>Fix: Import Organization merge options now appends attributes if keep existing user details is selected, and replaces attributes if update user details from the directory is selected.</li>
<li>Fix: Import Organization merge no longer replaces user&#8217;s passwords.</li>
<li>Fix: Fixed issue where no results were returned when filtering on time less than one day – such as past n hours.</li>
<li>Fix: Storages are no longer duplicated in the Import new hits task dialog.</li>
<li>Fix: Fixed issues where the Site Domain summary included sub-domains for European domains (.fr, .be etc).</li>
<li>Fix: SQL server inputs now commit correctly if the user edits the input and only changes the port number.</li>
</ul>
<h3>Loader Changes</h3>
<ul>
<li>New: IronPort Traffic Monitor Logs.</li>
<li>New: Juniper JunOS Traffic Logs (SRX).</li>
<li>New: Microsoft Exchange 2010.</li>
<li>New: Squid Syslog.</li>
<li>Improved: Astaro Security Gateway: Added support for an additional different syslog header.</li>
<li>Improved: SonicWall: Split syslog format into Web and Firewall schemas, added support for User field, string-type Category field and split Protocol field.</li>
<li>Fix: Microsoft FTMG: Changed type of Object Source field in from Int32 to String. Users will need to clear/field select/reload their storages before this change will apply.</li>
<li>Fix: Astaro Mail Gateway: Improved format detection, fixed negative size issue, and Index out of bounds errors.</li>
<li>Fix: IronPort WSA: Improved format detection.</li>
</ul>
<p><strong>How to update</strong></p>
<p>To update your software, simply click <strong>Tools | Check for updates</strong>. Vantage Ultimate users will also need to update the Web Module in order to use the new loader formats that have been added. To update the Vantage Web Module, right-click the WebSpy system tray icon and select ‘Check for updates’. If you have issues with the Web Module update process, please see: <a title="Web Module Update Issues" href="http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29</a></p>
<p>Let me know if you have any questions or issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-68-exchange-2010-juniper-and-ironport-traffic-logs-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.55 (Clearswift, Palo Alto Networks, WatchGuard and more)</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/#comments</comments>
		<pubDate>Tue, 12 Oct 2010 07:25:56 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[ClearSwift]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[FlowMonitor]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Partners]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ASA]]></category>
		<category><![CDATA[IOS Firewall]]></category>
		<category><![CDATA[ISA Server]]></category>
		<category><![CDATA[Microsoft ISA]]></category>
		<category><![CDATA[PA Firewall]]></category>
		<category><![CDATA[Palo Alto Networks]]></category>
		<category><![CDATA[PIX]]></category>
		<category><![CDATA[SECURE Web Gateway]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Syslog]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[Watchguard]]></category>
		<category><![CDATA[Web Security Appliance]]></category>
		<category><![CDATA[XTM]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2196</guid>
		<description><![CDATA[We&#8217;ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats.
What&#8217;s New?
Clearswift SECURE Web Gateway W3C
Clearswift have just released the latest version of their SECURE Web Gateway, which includes a transaction log export function. This enables you to send transaction logs [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an auto update for the Vantage software range. This release includes some new log format additions, and some fixes to existing formats.<span id="more-2196"></span></p>
<h2>What&#8217;s New?</h2>
<h3>Clearswift SECURE Web Gateway W3C</h3>
<p>Clearswift have just released the latest version of their SECURE Web Gateway, which includes a transaction log export function. This enables you to send transaction logs in W3C format to an off-box FTP server for analysis. If you are updating to the latest Clearswift SECURE Web Gateway, make sure you update your Vantage software to 2.2.0.55 in order to import your W3C Transaction logs. <a title="Using WebSpy Vantage with ClearSwift SECURE Web Gateway" href="http://www.webspy.com/vendors/clearswift/howto.aspx" target="_blank">More information on using WebSpy Vantage with Clearswift SECURE Web Gateway</a>.</p>
<h3>Cisco Firewall Bandwidth loader</h3>
<p>We have also introduced a new Loader for Cisco ASA, PIX and IOS Firewall devices. This new loader imports TCP, UDP, ICMP and GRE &#8217;session close&#8217; events into one schema, allowing you to aggregate size values across these  events. This loader is called Cisco Firewall (Bandwidth) and is now available on the Loader Selection page of the Import Wizard. Previously, these events were imported into separate schemas so there was no great way to determine total bandwidth from your Cisco syslog files (<a title="How to report on bandwidth utilization using Netflow and WebSpy FlowMonitor" href="http://www.webspy.com.au/blogs/index.php/how-to-report-on-bandwidth-utilization-using-cisco-devices/" target="_blank">without using Netflow and WebSpy FlowMonitor</a>).</p>
<h3>Palo Alto Networks and WatchGuard XTM</h3>
<p>We&#8217;re also very happy to welcome Palo Alto Networks to the WebSpy supported log file list. Vantage now supports both the CSV and syslog file formats from your PA Firewall.</p>
<p>Another new addition is support for the latest WatchGuard XTM devices running firmware version 11.</p>
<h2>Full List of Changes</h2>
<p>Here&#8217;s the full list of changes included in this update:</p>
<ul>
<li>New: Clearswift SECURE Web Gateway W3C.</li>
<li>New: Palo Alto Networks Firewall (CSV/Syslog)</li>
<li>New: Cisco Firewall (Bandwidth): This new Cisco loader imports TCP, UDP, ICMP and GRE events from ASA, PIX and IOS syslogs into one schema to aggregate size values across these events.</li>
<li>New: Added WatchGuard XTM: Currently http-proxy, https-proxy, smtp-proxy and firewall lines are supported.</li>
<li>Fixed: ISA Server: Fixed format detection issues, and issues importing hits with very large size values.</li>
<li>Fixed: IronPort WSA: Fixed format detection issues, as well as the import issue &#8220;Invalid value for DVS Scan Code&#8221;</li>
<li>Fixed: Sophos WSA: Fixed format detection issues and invalid line issues.</li>
</ul>
<h2>How to update</h2>
<p>To update your software, simply click <strong>Tools | Check for updates</strong>. To update the Vantage Web Module, right-click the WebSpy system tray icon and select &#8216;Check for updates&#8217;. If you have issues with the Web Module update process, please see: <a title="Web Module Update Issues" href="http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29" target="_blank">http://www.webspy.com.au/forums/viewtopic.php?f=4&amp;t=29</a></p>
<p>Let me know if you have any questions or issues!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-2-2-0-55-clearswift-palo-alto-networks-watchguard-and-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.48 &#8211; New Loaders, Features and Fixes</title>
		<link>http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 06:43:53 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Reports]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[errors]]></category>
		<category><![CDATA[fixes]]></category>
		<category><![CDATA[storages]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=2003</guid>
		<description><![CDATA[We&#8217;ve just released an update to the Vantage range of application, including the Web Module.
This release will be welcomed with open arms by many customers for the following reasons:

General usability improvements in the Web Module
Multi-select / delete options, Ajax progress indicators to avoid page refreshes, export from Dynamics Report tab and more (see below)
Fixes to [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an update to the Vantage range of application, including the Web Module.</p>
<p>This release will be welcomed with open arms by many customers for the following reasons:</p>
<ul>
<li><strong>General usability improvements in the Web Module</strong><br />
Multi-select / delete options, Ajax progress indicators to avoid page refreshes, export from Dynamics Report tab and more (see below)</li>
<li><strong>Fixes to the Microsoft Forefront TMG loader </strong><br />
See my other post: <a title="Microsoft Forefront TMG logs size fields the wrong way around" href="http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around" target="_blank">Microsoft Forefront TMG logs size fields the wrong way around</a>. Also fixed &#8216;value cannot be null&#8217; error when importing SQL logs.</li>
<li><strong>Fixes to storage corruption issues</strong><br />
This build should prevent &#8216;Normalization Index&#8217; storage corruption issues from occurring. This often occurred after importing data, editing some log inputs and reimporting.</li>
<li><strong>New loaders and more fixes</strong><br />
See below for the full list</li>
</ul>
<p><span id="more-2003"></span><br />
To update your Vantage application, simply choose <strong>Tools | Check for updates</strong>. To update the Web Module, right-click the WebSpy icon in your system tray and select &#8216;Check for updates&#8217;. If you have any issues updating the Web Module, please see my previous post <a title="Web Module Update Errors and Workarounds" href="http://www.webspy.com.au/blogs/index.php/web-module-update-errors-and-workaround/" target="_blank">Web Module Update Errors and Workarounds</a>.</p>
<p><strong>Web Module Changes:</strong></p>
<ul>
<li>New: Task progress is now updated without refreshing the page</li>
<li>New: Added multi-select / delete functionality to Reports, Analyses and Storages tables.</li>
<li>New: Added export functionality to Dynamic Reports view.</li>
<li>New: Added Performance section on the Options tab to enabling multi-processing (improves Analysis speed)</li>
<li>Fix: Dynamic Reports view now supports Trend reports.</li>
<li>Fix: Organization selector on Dynamic Reports view now always reflects updated data under IE6/7/8.Fix: Fixed javascript errors in IE when expanding the organization filter.</li>
<li>Fix: Report template names are no longer truncated on the Dynamic Reports view.</li>
<li>Fix: Fixed errors that may occur when collating reports on the Dynamic Reports page.</li>
<li>Fix: Authentication errors are now logged with stack trace.</li>
</ul>
<p><strong>Vantage Changes</strong></p>
<ul>
<li>Fixed: &#8216;Normalization index&#8217; storage corruption problems.</li>
<li>Fix: Report collation: Added support for collation of Min/Max aggregates on DateTime columns (time of first hit etc). Also added support for arrayed fields (for example, category fields with a comma separated list of categories)</li>
<li>Fix: Import windows wizard now remembers settings for Import all or selected users</li>
<li>Fix: Organization: Filtered LDIFs may now be imported when references to some users are missing (for example, if a user’s manager does not exist in the LDIF)</li>
<li>Fix: Improved connection and error handling between Vantage and the Web Module.</li>
</ul>
<p><strong> Loader Changes</strong></p>
<ul>
<li> New: BlueReef Sonar Total Management Module</li>
<li>New: Microsoft Sharepoint 2007</li>
<li>New: SmoothWall Guardian 7.0 format</li>
<li>New: Sun One Proxy (Supported under Sun One Webserver)</li>
<li>Fixed: Astaro: Improved format detection</li>
<li>Fixed: Cisco: Strings in the IP fields of 113019 lines are now imported</li>
<li>Fixed: IronPort WSA: Improved log format detection</li>
<li>Fixed: Microsoft Exchange 2007: No longer raises issues regarding total-bytes or internal-message-id fields</li>
<li>Fixed: Micorosft FTMG (Web) SQL: No longer encounters value could not be null errors</li>
<li>Fixed: Microsoft FTMG: Added option to reverse bytes received/sent fields. See <a href="http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-logs-size-fields-the-wrong-way-around" target="_blank">Microsoft Forefront TMG logs size fields the wrong way around</a></li>
<li>Fixed: Microsoft IIS W3C: Now imports cs-method and connection ID</li>
<li>Fixed: Sophos Web Appliance: Switched the outgoing and ingoing sizes so that they are now the correct way around</li>
<li>Fixed: Fixed import new hits issue associated with W3C formats. You must reload your logs before this change will take affect. Formats affected include: BlueCoat, Clearswift, Microsoft Exchange 2007, Microsoft FTMG, Microsoft Windows Media Services, WebSpy Live Tracking Log</li>
</ul>
<p>Enjoy!</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 801px; width: 1px; height: 1px; overflow: hidden;">
<h2>Microsoft Forefront TMG logs size fields the wrong way around</h2>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/new-vantage-update-2-2-0-48/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.43</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/#comments</comments>
		<pubDate>Thu, 20 May 2010 06:45:45 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Tips and Best Practices]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Module]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Astaro]]></category>
		<category><![CDATA[Barracuda]]></category>
		<category><![CDATA[BlueCoat]]></category>
		<category><![CDATA[ClearSwift]]></category>
		<category><![CDATA[dynamic reports]]></category>
		<category><![CDATA[FTMG]]></category>
		<category><![CDATA[IIS]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[microsoft Forefront TMG]]></category>
		<category><![CDATA[NetAsq]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1511</guid>
		<description><![CDATA[We've just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module. This is a great update for Vantage Ultimate users as we've introduced a new feature/tab into the Web Module called 'Dynamic Reports'.

Here's the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just released an auto update for WebSpy Vantage (Premium, Giga and Ultimate) as well as the Web Module.</p>
<p>This is a great update for Vantage Ultimate users as we&#8217;ve introduced a new feature/tab into the Web Module called &#8216;Dynamic Reports&#8217;.</p>
<p>If you&#8217;re publishing the same report to the Web Module each day, you can use the Dynamic Reports tab to select a date range and a department (or whatever organizational groups you have defined) and the Web Module will collate all the daily reports that match that filter into one report. This allows you to report on entire week, month or year by simply &#8216;reporting on reports&#8217;, rather than reporting months of raw storage data.</p>
<p>Here&#8217;s the full list of changes since the last auto update (2.2.0.32 on the 14th April 2010).</p>
<p><strong>Application Changes</strong></p>
<ul>
<li>Added Dynamic Reports feature to the Web Module.</li>
<li>Rewrote the Web Module transfer protocol. New protocol adds version checking, connection checking, and integrity checking for high latency environments.</li>
<li>Purge data from storage task no longer prevents importing new hits when all data is removed from an input within a storage.</li>
<li>IPv6 addresses now show IPv4-mapped addresses as plain IPv4 addresses in summaries.</li>
<li>IPv6 and IPv4 addresses are now freely interchangable in filter expressions.</li>
<li>Fixed IPv6 drilldowns on the Summaries screen</li>
<li>SQL inputs can now be resumed from the previous position. Previously any input that was partially imported would be skipped when importing new hits.</li>
<li>Template-based analysis has been fixed, no longer results in blank/non-existent analysis.</li>
<li>Added new string manipulation functions to expression language; Contains, StartsWith, EndsWith, IndexOf.</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>Astaro: Now checks that the ID field is present in a line before attempting to read it.</li>
<li>Barracuda Web Filter: Added this format to replace Spy Filter.</li>
<li>BlueCoat Proxy SG W3C: Added support for gmttime, timestamp, x-bluecoat-surfcontrol-is-denied and x-bluecoat-transaction-id.</li>
<li>ClearSwift: Added a new loader group for ClearSwift that includes the MimeSweeper loaders</li>
<li>ClearSwift SECURE Web Gatway: Now supported with the Web Appliance loader</li>
<li>Clearswift Web Appliance: User summary displays Source IP if Username is blank.</li>
<li>IronPort WSA: Fixed memory usage issues.</li>
<li>Microsoft FTMG: Added category name lookup to SQL loader.</li>
<li>Microsoft FTMG: No longer fails to import lines where the rule field contains square brackets.</li>
<li>Microsoft FTMG: URL Category field is now a string instead of an integer. Added URL Categorization Reason field.</li>
<li>Microsoft FTMG: Fixed memory usage issues.</li>
<li>Microsoft IIS W3C: No longer hangs or crashes when loading a file that isn&#8217;t IIS W3C.</li>
<li>NetAsq: Added support for srcname field. The Username summary is populated with user first, and then srcname if user is blank. The User summary is also now populated with Source IPs if the Username summary is blank.</li>
</ul>
<p>To update WebSpy Vantage, simple select Tools | Check for updates.</p>
<p>To update the Web Module, login to the Web Module server, right-click the WebSpy system tray icon, and select Check for updates.</p>
<p>As always, please <a title="Contact WebSpy" href="http://www.webspy.com/about/contact.aspx" target="_blank">contact us</a> if you have any issues or questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22043/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vantage Update 2.2.0.29 &#8211; New Fields for IronPort</title>
		<link>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 06:55:01 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[System Administration]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[bytes received]]></category>
		<category><![CDATA[bytes sent]]></category>
		<category><![CDATA[fields]]></category>
		<category><![CDATA[group]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[WebSpy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=1282</guid>
		<description><![CDATA[We have just added support for the 'Group' field in IronPort's access logs. You can add this field to your logs by adding %g in the 'Custom Fields' edit box. We have also added support for the custom fields Body Request Size and Body Response Size.]]></description>
			<content:encoded><![CDATA[<p>We have just added support for the &#8216;Group&#8217; field in IronPort&#8217;s access logs. You can add this field to your logs by adding %g in the &#8216;Custom Fields&#8217; edit box (on your IronPort WSA appliance  under System Administration | Log Subscriptions | accesslogs).</p>
<p>When imported into WebSpy Vantage, the result is shown in a new summary called &#8216;Group&#8217; which you can add to your reports.<span id="more-1282"></span></p>
<p><del datetime="2010-03-16T01:30:47+00:00">We also added support for the custom fields Bytes Sent and Bytes Received. Due to the absence of a header in the IronPort access log, Bytes Received and Bytes Sent fields must both be present to be detected, and the Received field must precede the Sent field.</del></p>
<p>We also added support for the custom fields Request Body Size and Response Body Size. These fields can be included in your access log by adding %q (Request body size) and %b (Response body size)  in the &#8216;Custom Fields&#8217; edit box. Due to the absence of a header in the IronPort access log, Request Body Size and Response Body Size fields must both be present to be detected, and the Request field must precede the Response field.</p>
<p><del datetime="2010-03-16T01:30:47+00:00">We&#8217;ve also noticed that the values in the Bytes Sent and Bytes Received fields do not necessarily add up to the value logged for &#8216;Size&#8217;. We&#8217;re discussing this issue with our friends at IronPort and we will hopefully post a solution or explanation soon.</del>.<br />
The information we first received about these fields indicated they represented Bytes Sent and Bytes Received. This is the way they are represented in the builds below (2.2.0.29). We will release a new build soon, with the field names changed to Request body size and Response body size. Body size is different to bytes sent/received as it does not include bytes from packet headers etc.</p>
<p>We&#8217;re yet to issue an automatic update for the Vantage applications, so in the mean time you can download the latest builds here:</p>
<p>Vantage Ultimate:<br />
<a title="Vantage Ultimate 2.2.0.29" href="ftp://ftp.webspy.com/webspy/Builds/VantageUltimate2.2.0.29.zip" target="_blank"> ftp://ftp.webspy.com/webspy/Builds/VantageUltimate2.2.0.29.zip</a></p>
<p>Vantage Web Module:<br />
<a href="ftp://ftp.webspy.com/webspy/Builds/VantageWebModule2.2.0.8.exe">ftp://ftp.webspy.com/webspy/Builds/VantageWebModule2.2.0.8.exe</a></p>
<p>Vantage Giga:<br />
<a title="Vantage Giga 2.2.0.27" href="ftp://ftp.webspy.com/webspy/Builds/VantageGiga2.2.0.29.zip" target="_blank">ftp://ftp.webspy.com/webspy/Builds/VantageGiga2.2.0.29.zip</a></p>
<p>Vantage Premium:<br />
<a title="Vantage Premium 2.2.0.29" href="ftp://ftp.webspy.com/webspy/Builds/VantagePremium.2.0.29.zip" target="_blank">ftp://ftp.webspy.com/webspy/Builds/VantagePremium2.2.0.29.zip</a></p>
<p><strong>To apply the Vantage update</strong>, close Vantage and extract the downloaded file into Vantage’s installation folder (Usually c:\Program Files\WebSpy\Vantage &lt;flavour&gt; 2.2). Overwrite the existing files.</p>
<p><strong>To apply the Web Module update</strong>, uninstall the Vantage Web Module from Add/Remove Programs (Programs and Features in Windows 7/Server 2008), then run the downloaded exe file, making sure you specify the same server, virtual directory and data location that your Web Module was previously using.</p>
<p>We will be releasing this as a public auto-update soon. Let us know if you have any issues.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/vantage-update-22029-new-fields-for-ironport/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Forefront TMG Release Candidate now available</title>
		<link>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-release-candidate-now-available/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-release-candidate-now-available/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 01:00:34 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft ISA Server]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Third Party]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[release candidate]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[TMG]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=734</guid>
		<description><![CDATA[Microsoft have announced the availability of Microsoft Forefront Threat Management Gateway (TMG) Release Candidate (RC).  This is the final public release of TMG before it is made available to purchase. 

If you're considering upgrading your ISA Server to TMG, this means that you can start your deployment using the Release Candidate, and simply switch it to a licenced version with no additional configuration changes once the full release is available.]]></description>
			<content:encoded><![CDATA[<p>Microsoft has announced the availability of Microsoft Forefront Threat Management Gateway (TMG) Release Candidate (RC).  This is the final public release of TMG before it is made available to purchase. </p>
<p>If you&#8217;re considering upgrading your ISA Server to TMG, this means that you can start your deployment using the Release Candidate, and simply switch it to a licensed version with no additional configuration changes once the full release is available.<span id="more-734"></span> At least, that is what Vladimir Holostov (Lead Program Manager, Release Manager for Forefront TMG 2010) states on the Forefront TMG (ISA Server) Product Team Blog:</p>
<blockquote><p>&#8220;The final product will be released later this year and you can expect it to behave exactly like the Release Candidate. You can install Forefront TMG 2010 RC today and upgrade to a licensed version once available without changing the configuration of your deployment.&#8221; </p></blockquote>
<p>To offer some peace of mind for organizations considering the deployment, Vladimir also mentions that &#8220;Forefront TMG 2010 RC is deployed at three major Microsoft sites located around the world in Haifa, Bellevue and Redmond. More than 20,000 employees are already protected by TMG and these deployments have already accumulated more than 5,000 hours of runtime, performing extremely well under heavy load&#8221;.</p>
<p>No major features have been added to the Release Candidate since Beta 3, however there have been improvements geared around tightening up security, reliability and performance and telemetry. For more information about the release candidate, please visit the<br />
<a href="http://blogs.technet.com/isablog/archive/2009/10/11/forefront-threat-management-gateway-2010-release-candidate-now-available.aspx" target="_blank">Forefront TMG (ISA Server) Product Team Blog</a>. </p>
<p>You can also download the release candidate <a href="http://www.microsoft.com/DOWNLOADS/details.aspx?FamilyID=e05aecbc-d0eb-4e0f-a5db-8f236995bccd&#038;displaylang=en" target="_blank">here</a></p>
<p>I mentioned in my last blog posting that WebSpy has introduced support for reporting on Microsoft Forefront TMG log formats in the Vantage product range. To try it out, please make sure you have installed Vantage 2.2 (any flavour &#8211; Premium, Giga or Ultimate), and then select <strong>Tools | Check for updates </strong>to download build 2.2.0.10 or above.  You can then import your TMG log files by selecting the Microsoft FTMG loader in the import wizard.<br />
<div id="attachment_596" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg.png"><img src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg-300x225.png" alt="Importing Microsoft Forefront Threat Management Gateway Log Files" title="Importing Microsoft Forefront Threat Management Gateway Log Files" width="300" height="225" class="size-medium wp-image-596" /></a><p class="wp-caption-text">Importing Microsoft Forefront Threat Management Gateway Log Files</p></div></p>
<p>We&#8217;re very interested to hear your thoughts on the reporting functionality, so please go ahead and give it a go!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/microsoft-forefront-tmg-release-candidate-now-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exciting New Features in Vantage Update 2.2.0.10</title>
		<link>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/#comments</comments>
		<pubDate>Wed, 09 Sep 2009 07:27:29 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Threat Management Gateway]]></category>
		<category><![CDATA[Scheduled Tasks]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[WebSpy News Update]]></category>
		<category><![CDATA[Bug Fixes]]></category>
		<category><![CDATA[CSV]]></category>
		<category><![CDATA[Data Purge]]></category>
		<category><![CDATA[ExoServer]]></category>
		<category><![CDATA[Forefront]]></category>
		<category><![CDATA[Import Organization]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[IronPort]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[New Features]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[Tasks]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=593</guid>
		<description><![CDATA[Attention all Vantage customers (and triallers). We've just released build 2.2.0.8 as an auto-update. This build includes new features such as scheduled data purge, support for Microsoft Forefront Threat Management Gateway, and scheduling CSV imports into your Organizational structure.]]></description>
			<content:encoded><![CDATA[<p>Attention all Vantage customers (and evaluators). We&#8217;ve just released build 2.2.0.10 as an auto-update. This build includes support for Microsoft Forefront Threat Management Gateway, and new features such as scheduled &#8216;data purge&#8217; and scheduling CSV imports into your Organizational structure.</p>
<p><span id="more-593"></span></p>
<p>You should be prompted to update your software on startup, but if you&#8217;ve turned off that feature, simply go to <strong>Tools | Check for Updates</strong>.</p>
<h2>New Features</h2>
<p>This new build sports the following new features:</p>
<ul>
<li> <strong>Support for Microsoft Forefront Threat Management Gateway (Beta)</strong><br />Microsoft Forefront Threat Management Gateway (FTMG) is still currently in Beta, and is due to be released around November 2009. For those that do not know, FTMG is the next version of Microsoft&#8217;s popular ISA Server. Information and downloads for FTMG can be found here <a href="http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/tmg-beta.aspx">http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/tmg-beta.aspx</a>. We have added support for FTMG beta 2 and 3 for both the W3C text logs (recommended) and the internal SQL Server Express Database logs. If you are currently trialling FTMG, we are very interested to hear your feedback. Let us know how you go!
<div id="attachment_596" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg.png"><img class="size-medium wp-image-596 " title="Now Supported - Microsoft Forefront Threat Management Gateway" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/microsoft-ftmg-300x225.png" alt="Microsoft Forefront Threat Management Gateway" width="300" height="225" /></a><p class="wp-caption-text">Now Supported - Microsoft Forefront Threat Management Gateway</p></div></li>
<li><span style="background-color: #ffffff;"><strong>Data purge</strong><br />
You can now purge data from a storage, and schedule this purge to occur on a regular basis using Tasks. Purge options include data between a date range, data before a date, data after a date, data older than a date relative to now, and all data. This feature will let you easily maintain a single storage that only includes data for the last month or day.</p>
<p><div id="attachment_594" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/purge-storage.png"><img class="size-medium wp-image-594" title="Purge Storage Wizard" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/purge-storage-300x225.png" alt="Options for Purging data from your storage" width="300" height="225" /></a><p class="wp-caption-text">Options for Purging data from your storage</p></div>
<p></span></li>
<li><strong>Import Organization from CSV can now be scheduled using Tasks</strong><br />
<span style="font-weight: normal;"><span style="background-color: #ffffff;">If you are importing your organizational structure from CSV, you can now schedule this action using Tasks. This enables you to update your organizational structure before any reports are run.</span></span></p>
<p><div id="attachment_597" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-from-csv.png"><img class="size-medium wp-image-597" title="Import Organization from CSV via Tasks" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/09/import-organization-from-csv-300x224.png" alt="Import Organization from CSV via Tasks" width="300" height="224" /></a><p class="wp-caption-text">Import Organization from CSV via Tasks</p></div></li>
<li> <strong><span style="background-color: #ffffff;">Added Support for ExoServer Web</span></strong><br />
If you&#8217;re running ExoServer Web, you can now analyze it&#8217;s logs using WebSpy Vantage.</li>
</ul>
<h2>Fixes</h2>
<p>We also fixed some things that may have been bugging you:</p>
<ul>
<li><span style="background-color: #ffffff;">Improved the start time for the application by improving the logic to check for Storage damage.</span></li>
<li><span style="background-color: #ffffff;">Fixed the IronPort loader (Fixed out of range issues on excessive size fields).</span></li>
<li><span style="background-color: #ffffff;">&#8220;Having&#8221; filters no longer override the sort order of a Report Template node.</span></li>
<li><span style="background-color: #ffffff;">Fixed an issue that may result in duplicated storages after migrating settings from earlier versions.</span></li>
<li><span style="background-color: #ffffff;">Fixed the inability to remove invalid entities from web module permissions list (users that no longer exist).</span></li>
<li>Fixed a timeout issue when publishing storages to the web module.</li>
</ul>
<p>Why are you still reading? Go update now!</p>
<p>Have fun!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/exciting-new-features-in-vantage-update-22010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updates to Vantage, Analyzer &amp; Live</title>
		<link>http://www.webspy.com.au/blogs/index.php/updates-to-vantage-analyzer-live/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/updates-to-vantage-analyzer-live/#comments</comments>
		<pubDate>Fri, 17 Apr 2009 05:55:58 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Live]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Software Updates]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=105</guid>
		<description><![CDATA[We’ve issued a bunch of auto updates for nearly all WebSpy products today

 

Of particular note is a fix to the Vantage range:

·         Fix: Improved partition matching when filtering by a date range

 

This will benefit you if you're running reports with a date range filter such as last week or yesterday (which is pretty much everyone), and are using the default storage partitioning scheme of "Date" (again... pretty much everyone). ]]></description>
			<content:encoded><![CDATA[<p>We’ve issued a bunch of auto updates for nearly all WebSpy products today</p>
<p>Of particular note is a fix to the Vantage range:</p>
<ul>
<li>Fix: Improved partition matching when filtering by a date range</li>
</ul>
<p>This will benefit you if you&#8217;re running reports with a date range filter such as last week or yesterday (which is pretty much everyone), and are using the default storage partitioning scheme of &#8220;Date&#8221; (again&#8230; pretty much everyone).<span id="more-105"></span></p>
<p>There was an issue in Vantage’s partition filtering technology which meant that if you specified a date range filter, Vantage would still analyse an entire storage, instead of just the date partitions you selected in the filter.</p>
<p>So do a <strong>Tools | Check for updates</strong> to grab build 2.1.2.12 and you should see a significant speed improvement in report generation. Woo hoo!</p>
<p>Here&#8217;s more details on the changes:</p>
<h3>VANTAGE</h3>
<p><strong>Application Changes</strong></p>
<ul>
<li>New: Added support for importing event logs from non-domain machines.</li>
<li>New: Added the ability for the Troubleshoot Alias/Profiles to export results to a file.</li>
<li>New: Added hash salt and substring functions to the expression language.</li>
<li>New: Added support for computing a date-modified file mask at import time and storing it back into the storage.</li>
<li>New: Added a file mask override to the Import new hits to existing storage task action.</li>
<li>New (Vantage Ulitmate &amp; Giga): Added support for attributes on Organization groups.</li>
<li>New (Vantage Ultimate): Added custom expression-based split in Web Module publishing (Beta).</li>
<li>New (Vantage Ultimate): Changed the publish report wizard to allow selection of multiple storages.</li>
<li>Fix: Improved partition matching when filtering by a date range.</li>
<li>Fix: Fixed an issue with registrations and trial extensions.</li>
<li>Fix: Fixed zero-width rectangle exceptions in chart renderer.</li>
<li>Fix: Fixed overflow exceptions on footer generation in report tables.</li>
<li>Fix: Fixed XmlException error during settings load.</li>
<li>Fix: Storage now clears previous data when it is overwritten when using the ‘Import logs into new storage’ task.</li>
<li>Fix (Vantage Ultimate &amp; Giga): Fixed issues with date range selection when collating reports.</li>
<li>Fix (Vantage Ultimate): Web Module dock no longer checks for updates to a web module server when ‘Check for updates on startup’ is disabled.</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>New: Added Phion Firewall</li>
<li>New: Added Watchguard Firebox X Core</li>
<li>New: Added NetScreen 208</li>
<li>New: Added IPCop</li>
<li>New: Added Astaro Mail Gateway</li>
<li>New: Added iPrism Monitor v4.2</li>
<li>New: Added Cisco VPN Concentrator</li>
<li>New: Added Snare for Lotus Notes</li>
<li>Improved: Added string host name to Kerio Mail Server</li>
<li>Improved: Improved support for NetIntact PacketLogic</li>
<li>Fix: Made changes to the IronPort detection method to fix the issue when importing via FTP.</li>
<li>Fixed: Fixed date format issue in event log import. You can now import event logs in any regional configuration.</li>
<li>Fix: Postfix loader no longer drops session state after the first recipient line</li>
<li>Fix: Updated the detection method in CheckPoint Firewall-1 Syslog format.</li>
<li>Fix: Fixed an issue in iSheriff where a drilldown on the Category field would display no results.</li>
<li>Fix: Various fixes to Netscreen 10</li>
<li>Fix: Various fixes to Arkoon PxLog</li>
<li>Fix: Vaious fixes to Sendmail MTA</li>
</ul>
<h3>VANTAGE WEB MODULE</h3>
<ul>
<li>FIX: When sorting by key column the chart will now use the &#8220;hits&#8221; aggregate for value (prevents the chart from going wacky)</li>
</ul>
<h3>ANALYZER</h3>
<p><strong>Application Changes</strong></p>
<ul>
<li>NEW: Added support for manual configuration of ISA block list settings (Tools | Options | Block Lists)</li>
<li>Fix: Fixed an issue with registrations and trial extensions</li>
<li>Fix: Fixed report wizard configuration to restore the sort column from the report template</li>
</ul>
<p><strong>Loader Changes</strong></p>
<ul>
<li>New: Added Webroot</li>
<li>New: Added Qmail Desknow Mail Server</li>
<li>New: Added UserGate Proxy Server 2.7</li>
<li>New: Added Netgear FVX538</li>
<li>Improved: Added support for importing allowed/blocked status in Sophos Web format</li>
<li>Fixed: Changed CC Proxy field count check</li>
<li>Fixed: Changed ISA SQL loaders to use size delta fields instead of cumulative fields</li>
<li>Fixed: Modified Exchange 2000/2003 loader to discard message cache after import</li>
</ul>
<h3>LIVE</h3>
<p><strong>Application changes</strong></p>
<ul>
<li>Fix: Fixed an issue with registrations and trial extensions</li>
</ul>
<p><strong>Loader changes:</strong></p>
<ul>
<li>New: Added Webroot</li>
<li>New: Added Qmail Desknow Mail Server</li>
<li>New: Added UserGate Proxy Server 2.7</li>
<li>New: Added Netgear FVX538</li>
<li>Improved: Added support for importing allowed/blocked status in Sophos Web format</li>
<li>Fixed: Changed CC Proxy field count check</li>
<li>Fixed: Modified Exchange 2000/2003 loader to discard message cache after import</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/updates-to-vantage-analyzer-live/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enhancement to the Sophos Loader in Analyzer</title>
		<link>http://www.webspy.com.au/blogs/index.php/enhancement-to-the-sophos-loader-in-analyzer/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/enhancement-to-the-sophos-loader-in-analyzer/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 01:42:42 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Analyzer]]></category>
		<category><![CDATA[Firewall Analysis]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Web Browsing Analysis]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Blocked]]></category>
		<category><![CDATA[Importing]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Not Blocked]]></category>
		<category><![CDATA[Sophos]]></category>
		<category><![CDATA[Web Security Appliance]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=71</guid>
		<description><![CDATA[We’ve made a modification to Analyzer’s Sophos loader so that it takes the value from the action field to determine blocked/allowed.

The fix can be applied to WebSpy Analyzer Giga 2.3, Analyzer Premium 4.3 or Analyzer Standard 4.3]]></description>
			<content:encoded><![CDATA[<p>We’ve made a modification to Analyzer’s Sophos Web Security Appliance loader so that it takes the value from the action field to determine blocked/allowed.</p>
<p>The fix can be applied to WebSpy Analyzer Giga 2.3, Analyzer Premium 4.3 or Analyzer Standard 4.3. <span id="more-71"></span>If you&#8217;re not running the latest version, <a href="http://www.webspy.com/products/analyzer/download.aspx">download it now!</a></p>
<p>You can download the new loader build that we created today at either of these locations:<br />
<a href="ftp://ftp.webspy.com/webspy/Builds/Loader4.3.2.6.zip">USA West Coast (FTP)</a><br />
<a href="ftp://ftpwest.webspy.com/webspy/Builds/Loader4.3.2.6.zip">USA East Coast (FTP)</a></p>
<p>Then extract the zip file into Analyzer&#8217;s installation folder (usually C:\Program Files\WebSpy\Analyzer <em>flavour</em> 4.3\) and overwrite the existing file.</p>
<p>Then go to the storages screen and select your Sophos storage(s) and click ‘Reload all hits’. This will re-import your log files using the modified loader and will populated the ‘Blocked’ summary appropriately.  To check it out, go to the Summaries screen and run a Full Analysis. Then go to the &#8216;Blocked&#8217; summary and you should see two items &#8211; &#8216;Blocked&#8217; and &#8216;Not Blocked&#8217;. Drilldown into whichever one you care about to analyze the sites, users, files, browsing times, size downloaded etc. Go nuts!</p>
<p>You can also filter out blocked hits (or Not Blocked hits) from your reports. On the Reports Screen, click Generate a new report and go through the report wizard with this filter (this example shows filtering out blocked hits).</p>
<div id="attachment_72" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-custom_filters.jpg"><img class="size-medium wp-image-72" title="Analyzer Report Wizard - Select Custom Filters" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-custom_filters-300x230.jpg" alt="Analyzer Report Wizard - Select Custom Filters" width="300" height="230" /></a><p class="wp-caption-text">Analyzer Report Wizard - Select Custom Filters</p></div>
<div id="attachment_73" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_filter.jpg"><img class="size-medium wp-image-73" title="Analyzer Report Wizard - Selecting the 'Blocked' Summary as a Filter" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_filter-300x230.jpg" alt="Analyzer Report Wizard - Selecting the 'Blocked' Summary as a Filter" width="300" height="230" /></a><p class="wp-caption-text">Analyzer Report Wizard - Selecting the &#39;Blocked&#39; Summary as a Filter</p></div>
<div id="attachment_74" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard_add_blocked.jpg"><img class="size-medium wp-image-74" title="Analyzer Report Wizard - Adding the items that you want to filter" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard_add_blocked-300x232.jpg" alt="Analyzer Report Wizard - Adding the items that you want to filter" width="300" height="232" /></a><p class="wp-caption-text">Analyzer Report Wizard - Adding the items that you want to filter</p></div>
<div id="attachment_75" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_criteria.jpg"><img class="size-medium wp-image-75" title="Analyzer Report Wizard - final filter to exclude 'Blocked' hits" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/analyzer_report_wizard-blocked_criteria-300x230.jpg" alt="Analyzer Report Wizard - final filter to exclude 'Blocked' hits" width="300" height="230" /></a><p class="wp-caption-text">Analyzer Report Wizard - final filter to exclude &#39;Blocked&#39; hits</p></div>
<p>Then proceed through the report wizard to generate your report.  This filter can be applied to any report as well as analyses on the Summaries screen (using the same options in the Analysis Wizard).</p>
<p>Happy analyzing!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/enhancement-to-the-sophos-loader-in-analyzer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Counting Emails with Microsoft Exchange 2007 Tracking Logs</title>
		<link>http://www.webspy.com.au/blogs/index.php/counting-emails-with-microsoft-exchange-2007-tracking-logs/</link>
		<comments>http://www.webspy.com.au/blogs/index.php/counting-emails-with-microsoft-exchange-2007-tracking-logs/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 05:45:01 +0000</pubDate>
		<dc:creator>Scott</dc:creator>
				<category><![CDATA[Email Analysis]]></category>
		<category><![CDATA[How To]]></category>
		<category><![CDATA[Log File Analysis]]></category>
		<category><![CDATA[Microsoft Exchange]]></category>
		<category><![CDATA[Vantage]]></category>
		<category><![CDATA[WebSpy]]></category>
		<category><![CDATA[Exchange 2007]]></category>
		<category><![CDATA[Loaders]]></category>
		<category><![CDATA[Message Tracking Logs]]></category>
		<category><![CDATA[Recipient Count]]></category>

		<guid isPermaLink="false">http://www.webspy.com.au/blogs/?p=32</guid>
		<description><![CDATA[Today I've been poking at Microsoft Exchange 2007 tracking logs, asking them the very simple question of 'How many emails have I sent?'.

Unforunately, Exchange 2007 tracking logs are not used to simple questions, and are likely to return a complicated and / or misleading answer.

But the confusion it seems, all comes down to definitions. Once you understand these definintions, things start to make a bit more sense.]]></description>
			<content:encoded><![CDATA[<p>Today I&#8217;ve been poking at Microsoft Exchange 2007 tracking logs, asking them the very simple question of &#8216;How many emails have I sent?&#8217;.</p>
<p>Unfortunately, Exchange 2007 tracking logs are not used to simple questions, and are likely to return a complicated and / or misleading answer.</p>
<p>But the confusion it seems, all comes down to definitions. Once you understand these definintions, things start to make a bit more sense.<span id="more-32"></span></p>
<h3>What is an Email?</h3>
<p>If you send an email to one person, you&#8217;ve sent one email. But if you&#8217;ve sent that same email to 500 people, have you sent one email, or 500?  I will take a guess, and say that a large majority of you will want to see 500 in your reports.</p>
<p>Microsoft Exchange 2007 tracking logs contain an excellent field called &#8216;Message ID&#8217;.  If you send an email to someone, that message is uniquely identified by a Message ID that persists though Exchange&#8217;s various functions for the lifetime of the message.</p>
<p>At first glance, it seems that counting Message IDs will give us what we want. But if you send the same email to 500 recipients, all those emails get the same unique message ID. So counting message IDs will show us that only one email has been sent. No good.</p>
<p>Then next obvious step is to count the number of recipients that received the email.</p>
<h3>What is a Recipient?</h3>
<p>The definition of recipient can also get clouded when you start talking about distribution lists. If you send an email to one real person, then that is one recipient. If you send the same email to five real people then that is five recipients. If you send an email to an internal distribution list, the number of recipients is the number of people that are members of that distribution list.</p>
<p>If you send an email to an external distribution list (such as SalesDL@othercompany.com) this will only be recorded as only one recipient, as your Exchange box has no way of knowing how many real people  are members of that DL at the other company.</p>
<h3>How do I count Recipients?</h3>
<p>Again, Exchange Tracking logs contain another excellent field called &#8216;Recipient Count&#8217;.  But don&#8217;t get carried away as this too can be misleading.</p>
<p>Without going into specifics, Exchange has a bunch of internal functions to deal with an entire message transmission. The tracking logs files contain another excellent field called Internal Message ID that identifies each of these processes per-message.</p>
<p>Unfortunately, each Internal Message ID contains its own value for &#8216;Recipient Count&#8217;.  So when you sum the Recipient Count field for a single message, the final result may be much larger than the actual number of real recipients.</p>
<p>To illustrate, WebSpy Vantage imports Recipient Count into a Summary of the same name.  Here is a screenshot of the Recipient Count Summary for one message</p>
<div id="attachment_51" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007recipientcount.png"><img class="size-medium wp-image-51" title="The Exchange 07 'Recipient Count' Summary for a Single Message" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007recipientcount-300x236.png" alt="The Recipient Count Summary for a Single Message" width="300" height="236" /></a><p class="wp-caption-text">The Recipient Count Summary for a Single Message</p></div>
<p>As you can see, there are multiple rows of individual Recipient Counts. The first row, is actually correct. This email was actually sent to 961 people. But there are additional entries where Exchange performed an internal operation with a subset of those messages.  Therefore, summing the Recipient Count field for a message is also no good.</p>
<h3>Counting recipients &#8220;properly&#8221;</h3>
<p>The best way to count recipients is to use WebSpy Vantage to import your logs, then drilldown into a message to the Recipients summary and look at the total number of recipients at the bottom.  Alternatively, add a Count Distinct aggregate for the Recipients summary to any report template.</p>
<p>Here&#8217;s a screenshot of the Recipients summary:</p>
<div id="attachment_36" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007properrecipientcount.png"><img class="size-medium wp-image-36" title="The Recipients Summary showing Total 'Real' Recipients" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007properrecipientcount-300x192.png" alt="The Recipients Summary showing Total 'Real' Recipients" width="300" height="192" /></a><p class="wp-caption-text">The Recipients Summary showing Total &#39;Real&#39; Recipients</p></div>
<p>And here&#8217;s a screenshot showing how to add the aggregate to a report template:</p>
<div id="attachment_37" class="wp-caption aligncenter" style="width: 310px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007addingnumberofrecipientsaggregate.png"><img class="size-medium wp-image-37" title="Adding the Number of Recipients to a report template" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/exchange2007addingnumberofrecipientsaggregate-300x196.png" alt="Adding the Number of Recipients to a report template" width="300" height="196" /></a><p class="wp-caption-text">Adding the Number of Recipients to a report template</p></div>
<h3>Counting Total Number of Emails</h3>
<p>The above screenshot will give you a count of all the recipients you have ever sent email to. However, what you really want is a count of recipients <em>per message</em>. You can do this by concatenating the Recipient with the Message ID, and counting the total number of rows. To do this, edit the <em>Number of recipients</em> aggregate column above and enter [Recipient] + [MessageID] in the &#8216;Custom&#8217; edit box.</p>
<div id="attachment_50" class="wp-caption aligncenter" style="width: 422px"><a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/recipientplusmessageid.png"><img class="size-full wp-image-50" title="Recipient Plus MessageID" src="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/recipientplusmessageid.png" alt="Customizing an aggregate column to concatenate Recipient and MessageID" width="412" height="293" /></a><p class="wp-caption-text">Customizing an aggregate column to concatenate Recipient and MessageID</p></div>
<h3>Exchange 2007 Report Templates</h3>
<p>You can <a href="http://www.webspy.com.au/blogs/wp-content/uploads/2009/03/microsoftexchange2007.zip">download a WebSpy Vantage Templates file here</a> that includes three reports (Email Overview, User Email Activity, and Email Trends) that uses columns such as Number of Emails, Number of Unique Messages and Number of Recipients.<br />
<strong></strong></p>
<p><strong>Tip: </strong>You can convert any email template that has the schema &#8216;All Mail Schemas&#8217; into an Exchange 2007 template in order to report and filter using all the fields available in Exchange 2007.</p>
<p>To do this:</p>
<ol>
<li>Right click an &#8216;All Mail Schema&#8217; email template and select <strong>Duplicate</strong>.</li>
<li>Select Microsoft Exchange 2007 from the schema drop down and click <strong>OK</strong>.</li>
<li>When you edit the nodes in your new template, you will have access to all the fields that Exchange 2007 records.</li>
</ol>
<p>Cheers!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webspy.com.au/blogs/index.php/counting-emails-with-microsoft-exchange-2007-tracking-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

