Generating Rule Hit Count Reports for Security and Network Policies

This article explains how to generate a report that shows hit counts for policy rules in the account. The hit count reports are available for the Internet Firewall, WAN Firewall, and Network Rules policies.

Overview of Rule Hit Count Reports

Cato provides a Predefined Report template that shows how many times traffic matched policy rules during the report period. This helps you identify unused rules that can be removed, and optimize rule configuration to better match the required traffic scope. The hit count for a rule is based on the number of events generated by the rule. If a rule is set to not generate events, the hit count is zero.

You can generate hit count reports for these policies:

  • Internet Firewall

  • WAN Firewall

  • Network Rules

Create the template for the Scheduled or One-Time report with the sites and SDP users that are included in the report over the defined time range. By default, the Predefined Report template for hit count reports shows traffic and data for all sites and SDP users for the past week.

For more about working with Predefined Reports, see Cato Reports.

predefined_reports.png

Creating a Scheduled Hit Count Report

Create a new Scheduled report, and define the Filters for the items included in the report. Then define the Report Schedule which defines how often the report is generated - daily, weekly, or monthly. Generated reports are stored in the Cato Cloud, and they can be automatically emailed or downloaded. The Report Schedule also defines the time range that is covered by each report. The time range starts on 00:00 UTC (inclusive) at the start of each period, and ends on 00:00 UTC (non-inclusive) at the end of the period.

You can select the Mailing List of email addresses for the recipients, the list can include Cato Management Application admins and external users.

For more information about Mailing Lists, see Working with Mailing Lists.

To create a scheduled hit count report:

  1. From the navigation pane, select Monitoring > Reports.

  2. From the Predefined Reports tab, click New > Scheduled report. The Scheduled Report panel opens.

  3. Enter the Report Name for the Predefined Report.

  4. In Type, select the hit count report type for the relevant policy.

  5. (Optional) In Filters, select specific sites or users for the Predefined Report.

    By default, the Predefined Report includes all sites and users.

    To include multiple sites or users in the report, use the IN operator.

  6. In Report Schedule, configure these settings:

    1. Select the Frequency that the report is automatically sent: Daily, Weekly, or Monthly.

    2. For Weekly and Monthly Scheduled reports, in Every select the day that the report is sent.

  7. In Subscriptions, select the Mailing List that receives the report.

    You can click New to create a new mailing list.

  8. Click Save. The report template is added to the Predefined Reports tab.

Manually Generating a Scheduled Report

A new Scheduled report is generated based on the Report Schedule settings. For example, a weekly report configured for Monday, is generated every Monday. You can also choose to manually generate a Predefined Report, and the generated report uses the same time range based on the current day. If an admin manually generates a weekly report on a Tuesday, the time range for the report is the previous 7 days starting from that Tuesday, regardless of the starting day of the Scheduled report.

To manually generate a Scheduled report:

  1. From the navigation pane, select Monitoring > Reports.

  2. From the Predefined Reports tab, find the Scheduled report and click Generate.

  3. From the Generated Reports tab, find the report and click Download.

Creating a One-Time Hit Count Report

Create a new One-time report template, and define the Filters for the items included in the report. Then define the Time Range that the report covers.

To create a One-Time hit count report:

  1. From the navigation pane, select Monitoring > Reports.

  2. From the Predefined Reports tab, click New > One-time report. The One-time report panel opens.

  3. Enter the Report Name for the Predefined Report.

  4. In Type, select the hit count report type for the relevant policy.

  5. (Optional) In Filters, select specific sites or users for the Predefined Report.

    By default, the Predefined Report includes all sites and users.

    To include multiple sites or users in the report, use the IN operator.

  6. Select the Time Range of the report.

    For a Custom range, select start date (From) and the end date (To) for the Predefined Report.

  7. Click Save. The report template is added to the Predefined Reports tab.

    You can also click Save & Generate, and then the report is generated and you can download it from the Generated Reports tab.

Understanding the Hit Count Reports

The hit count for a rule is based on the number of events generated by the rule. If a rule is set to not generate events, the hit count is zero.

These are the sections in a hit count report:

  • Top/Least Rules

    • Top Matched Rules - List of the 20 most matched policy rules with the hit count for each rule

    • Least Matched Rules - List of the 20 least matched policy rules with the hit count for each rule

  • Rules Hit Count - Shows the list of all rules in order of priority with the number of events generated for each rule, the rule name, and the timestamp for the most recent generated event

Was this article helpful?

0 out of 0 found this helpful

0 comments

Add your comment