39. Reports » Devices » Filters
Clicking on a Filter anywhere in the Console opens a tab with specific data. The tab has sub-tabs at the bottom. Each sub-tab shares these common toolbar fields:
● Filters – Select the Filter of interest, or All. Administrators can limit which Filters guests can access● Time Range – Select a predefined range, or Custom… for a specific time interval
Most sub-tabs also provide an Export panel (email, print, or export as PDF, TEXT, JSON, or CSV) and a Refresh bar (press Generate to build the report, or select an automatic refresh interval). Sub-tabs can be re-arranged by drag and drop; the order described below is the default.
39.1. Filter Dashboard
This sub-tab displays widgets using data collected by Filters. Its configuration is global (not specific to just one Filter), so any changes here are also visible in other Filter Dashboards. The Reports » Dashboards chapter describes general dashboard operations.
39.2. Filter Graphs
In this sub-tab you can view a variety of Filter-related histograms for the selected Filter(s):
● Data Units – Select one or more data units:• Most Used – Frequently used data units• Anomalies – Anomalies mitigated by the chosen Filter(s)• Filtering Rules – Filtering rules detected by the selected Filter(s)• SW Firewall Rules – Filtering rules enforced by Netfilter• HW Firewall Rules – Filtering rules enforced by NIC hardware filters• Peak/Total Source IPs – Number of unique IP addresses sending traffic to the attacked destination(s)• Peak/Total CPU% – CPU usage by the Filter(s)• Peak/Total Used RAM – Amount of RAM used by the Filter(s)• Peak/Total Filtered Packets – Packets reported as blocked• Peak/Total Filtered Bits – Bits reported as blocked• Peak/Total Scrubbed Packets – Packets dropped by the capturing engine of the Filter(s)• Peak/Total Received Packets – Packets received by the Filter(s)• Peak/Total Packets/s – Packets per second analyzed by the Filter(s), also available as Passed and Scrubbed variants• Peak/Total Bits/s – Bit throughput analyzed by the Filter(s), also available as Passed and Scrubbed variants• Filtering Rule - <rule type> – Number of filtering rules found per rule type: IP Addresses, Packet Length, TimeToLive, IP Protocol, TCP Src Port, TCP Dst Port, UDP Src Port, UDP Dst Port, or Other• Total Excepted Rules – Whitelisted (excepted) filtering rules● Size – Choose a preset dimension or enter a custom size as “<X> x <Y>” where <X> and <Y> are the horizontal/vertical pixel counts● Title – Enter your own text as the title, or select one of these options:• Auto – Automatically generated title• None – No title● Legend – Select how detailed the legend should be: None, Brief, or Full● Consolidation – Graph consolidation reduces data resolution by averaging, minimizing, or maximizing values over fixed time intervals, optimizing visualization while maintaining overall trends:• Maximum – Shows peak spikes• Average – Displays average values• Minimum – Focuses on lower values● Grouping• Filters – Select this to produce a single graph for all chosen Filters● Stacking• Filters – Choose this option to view summed, stacked values for multiple Filters
39.3. Filter Events
In this sub-tab, you can view events generated by the chosen Filter(s) during the specified time interval.
39.4. Filter Instances
Lists one row per Filter instance — a single anomaly mitigation carried out by a Filter. The top bar holds the Filters selector, a Row Filtering Expression search field with its bookmarks (star) button, a Display selector, an Export panel, a Time Range selector, and a Refresh bar. Each row’s Status reads Active, Finished, or Pending.
● Display – How many columns the grid shows:▪ Brief – The default: №, Filter, Anomaly №, Anomaly, Prefix, From, Duration, Pkts/s, Bits/s, Peak Pkts/s and Peak Bits/s▪ Extended – Adds Status, Until, FW Peak Pkts/s, FW Peak Bits/s, Peak CPU% and Peak RAM▪ Full – Adds Decoder, Unit, Domain, Comparison, Threshold, IP Group, Pkts, Bits, FW Pass Pkts, FW Pass Bits, SW FW Scrubbed Pkts, SW FW Scrubbed Bits, HW FW Scrubbed Pkts, HW FW Scrubbed Bits, Flowspec Packets, Flowspec Bits, Flowspec Pkts/s, Flowspec Bits/s, Peak Flowspec Pkts/s, Peak Flowspec Bits/s, IPs, Parent Instance and Ticks
The Decoder, Unit, Domain, Comparison and Threshold columns describe the threshold rule behind the instance and are explained in Reports » Tools » Anomalies. The FW, SW FW and HW FW counters report the traffic the software and hardware firewalls passed and scrubbed, while Parent Instance links a spun-off instance back to the one that launched it.
39.5. Filtering Rule Archive
Shows the filtering rules the selected Filter(s) detected over the chosen time range. It is the same paged grid documented in Reports » Tools » Firewall » Filtering Rule Archive — with the same Brief, Extended and Full display modes, Row Filtering Expression, and per-rule packet-dump and flow-list buttons — scoped here to the current Filter.
39.6. Filtering Rule Distribution
Generates pie or donut charts of filtering-rule statistics for the selected Filter(s), decoder and time range. The Data Units, Chart Type, Chart Size and Slice Label options are the same as in Reports » Tools » Firewall » Filtering Rule Distribution.
39.7. Geo Distribution
Displays an interactive world map that shades each country by a chosen metric for the selected Filter(s), decoder and time range. The Data Unit picks the metric: Anomalies (the default), Avg. Pkts/s, Max. Pkts/s, Avg. Bits/s or Max. Bits/s.