39. Reports » Devices » Filters

Clicking on a Filter anywhere in the Console opens a tab with specific data. The tab has sub-tabs at the bottom. Each sub-tab shares these common toolbar fields:

Filters – Select the Filter of interest, or All. Administrators can limit which Filters guests can access
Time Range – Select a predefined range, or Custom… for a specific time interval

Most sub-tabs also provide an Export panel (email, print, or export as PDF, TEXT, JSON, or CSV) and a Refresh bar (press Generate to build the report, or select an automatic refresh interval). Sub-tabs can be re-arranged by drag and drop; the order described below is the default.

39.1. Filter Dashboard

This sub-tab displays widgets using data collected by Filters. Its configuration is global (not specific to just one Filter), so any changes here are also visible in other Filter Dashboards. The Reports » Dashboards chapter describes general dashboard operations.

39.2. Filter Graphs

In this sub-tab you can view a variety of Filter-related histograms for the selected Filter(s):

Data Units – Select one or more data units:
Most Used – Frequently used data units
Anomalies – Anomalies mitigated by the chosen Filter(s)
Filtering Rules – Filtering rules detected by the selected Filter(s)
SW Firewall Rules – Filtering rules enforced by Netfilter
HW Firewall Rules – Filtering rules enforced by NIC hardware filters
Peak/Total Source IPs – Number of unique IP addresses sending traffic to the attacked destination(s)
Peak/Total CPU% – CPU usage by the Filter(s)
Peak/Total Used RAM – Amount of RAM used by the Filter(s)
Peak/Total Filtered Packets – Packets reported as blocked
Peak/Total Filtered Bits – Bits reported as blocked
Peak/Total Scrubbed Packets – Packets dropped by the capturing engine of the Filter(s)
Peak/Total Received Packets – Packets received by the Filter(s)
Peak/Total Packets/s – Packets per second analyzed by the Filter(s), also available as Passed and Scrubbed variants
Peak/Total Bits/s – Bit throughput analyzed by the Filter(s), also available as Passed and Scrubbed variants
Filtering Rule - <rule type> – Number of filtering rules found per rule type: IP Addresses, Packet Length, TimeToLive, IP Protocol, TCP Src Port, TCP Dst Port, UDP Src Port, UDP Dst Port, or Other
Total Excepted Rules – Whitelisted (excepted) filtering rules
Size – Choose a preset dimension or enter a custom size as “<X> x <Y>” where <X> and <Y> are the horizontal/vertical pixel counts
Title – Enter your own text as the title, or select one of these options:
• Auto – Automatically generated title
• None – No title
Legend – Select how detailed the legend should be: None, Brief, or Full
● Consolidation – Graph consolidation reduces data resolution by averaging, minimizing, or maximizing values over fixed time intervals, optimizing visualization while maintaining overall trends:
• Maximum – Shows peak spikes
• Average – Displays average values
• Minimum – Focuses on lower values
● Grouping
• Filters – Select this to produce a single graph for all chosen Filters
● Stacking
• Filters – Choose this option to view summed, stacked values for multiple Filters

39.3. Filter Events

In this sub-tab, you can view events generated by the chosen Filter(s) during the specified time interval.

39.4. Filter Instances

Lists one row per Filter instance — a single anomaly mitigation carried out by a Filter. The top bar holds the Filters selector, a Row Filtering Expression search field with its bookmarks (star) button, a Display selector, an Export panel, a Time Range selector, and a Refresh bar. Each row’s Status reads Active, Finished, or Pending.

Display – How many columns the grid shows:
Brief – The default: №, Filter, Anomaly №, Anomaly, Prefix, From, Duration, Pkts/s, Bits/s, Peak Pkts/s and Peak Bits/s
Extended – Adds Status, Until, FW Peak Pkts/s, FW Peak Bits/s, Peak CPU% and Peak RAM
Full – Adds Decoder, Unit, Domain, Comparison, Threshold, IP Group, Pkts, Bits, FW Pass Pkts, FW Pass Bits, SW FW Scrubbed Pkts, SW FW Scrubbed Bits, HW FW Scrubbed Pkts, HW FW Scrubbed Bits, Flowspec Packets, Flowspec Bits, Flowspec Pkts/s, Flowspec Bits/s, Peak Flowspec Pkts/s, Peak Flowspec Bits/s, IPs, Parent Instance and Ticks

The Decoder, Unit, Domain, Comparison and Threshold columns describe the threshold rule behind the instance and are explained in Reports » Tools » Anomalies. The FW, SW FW and HW FW counters report the traffic the software and hardware firewalls passed and scrubbed, while Parent Instance links a spun-off instance back to the one that launched it.

39.5. Filtering Rule Archive

Shows the filtering rules the selected Filter(s) detected over the chosen time range. It is the same paged grid documented in Reports » Tools » Firewall » Filtering Rule Archive — with the same Brief, Extended and Full display modes, Row Filtering Expression, and per-rule packet-dump and flow-list buttons — scoped here to the current Filter.

39.6. Filtering Rule Distribution

Generates pie or donut charts of filtering-rule statistics for the selected Filter(s), decoder and time range. The Data Units, Chart Type, Chart Size and Slice Label options are the same as in Reports » Tools » Firewall » Filtering Rule Distribution.

39.7. Geo Distribution

Displays an interactive world map that shades each country by a chosen metric for the selected Filter(s), decoder and time range. The Data Unit picks the metric: Anomalies (the default), Avg. Pkts/s, Max. Pkts/s, Avg. Bits/s or Max. Bits/s.