41. Reports » IP Addresses & Groups

This chapter explains how to generate detailed traffic reports for any IP address, block, or group found in Network & Policy » [IP Zone].

Reports » IP Addresses allows you to quickly generate traffic reports for IP addresses and blocks, which can be entered manually on the upper side of the panel or selected from the expandable tree below.

Reports » IP Groups lists IP groups defined in IP Zones. Select an IP group to generate a traffic report for all IP blocks belonging to it. To search for a specific IP group, enter a sub-string contained in its name at the top of the panel.

Each traffic report tab has sub-tabs along the bottom. These sub-tabs share common toolbar fields:

Sensor Interfaces – Choose the Sensor Interfaces of interest. Administrators may limit which Sensors guest accounts see
Time Range – Select a predefined time range or Custom… to specify a particular interval

Most sub-tabs also provide an Export panel (email, print, or export the report) and a Refresh bar (press Generate to build the report, or select an automatic refresh interval). Sub-tabs can be re-arranged by drag and drop; the order described below is the default.

Note

The stored data is subject to the General Settings » Data Retention policy, so older data may no longer be available.

41.1. IP Dashboard

Here you can group the most relevant data collected for the chosen Sensor Interfaces and the selected IP address, block, or group. This dashboard’s configuration isn’t tied to a specific IP address, block, or group, so any changes you make also appear in other IP dashboards. The basics of dashboard operation are covered in Reports » Dashboards.

41.2. IP Graphs

You can generate IP graphs only for the IP addresses, blocks, and groups explicitly defined in your IP Zone(s) or that belong to a subnet with the IP Graphing parameter enabled.

Decoders – Choose which decoders interest you. New decoders can be defined in General Settings » Custom Decoders and enabled in General Settings » Graphs & Storage
Data UnitBits/s, Packets/s, Bytes/s, Bytes/day, Bytes/week, or Bytes/month
● Size – Choose a preset dimension or enter a custom size as “<X> x <Y>” where <X> and <Y> are the horizontal/vertical pixel counts
● Title – Enter your own text as the title, or select one of these options:
• Auto – Automatically generated title
• None – No title
● Legend – Select how detailed the legend should be: None, Brief, Extended, or Full
● Consolidation – Graph consolidation reduces data resolution by averaging, minimizing, or maximizing values over fixed time intervals, optimizing visualization while maintaining overall trends:
• Minimum – Focuses on lower values
• Average – Displays average values
• Maximum – Shows peak spikes
Direction – Select how to show the traffic direction:
• Both – Graph inbound (+ Y-axis) and outbound (– Y-axis)
• Inbound – Only inbound
• Outbound – Only outbound
• Swap – Swap inbound/outbound
Grouping
Sensor Interfaces – Creates a single graph for all selected interfaces
Subnet IPs – Uncheck to generate a separate traffic graph for each IP in a block or group (not recommended for large subnets)
Stacking – Only one stacking mode can be active at a time:
Off – No stacking
Decoders – Stack multiple decoders’ data
Sensor Interfaces – Stack data for multiple Sensor Interfaces. Requires the Sensor Interfaces Grouping option
Permissions
Permit Conflicting Decoders – If decoders can nest (e.g., TCP contains HTTP), stacking them reveals the most specific decoder. When selecting TCP and HTTP, TCP becomes “TCP OTHER” (showing non-HTTP TCP), while HTTP is shown in full. If you also select TCP+SYN, it may overlap HTTP traffic, causing a conflict (since TCP+SYN can appear in HTTP). Check this option to disable conflict detection for more intuitive (but potentially less accurate) graphs. Uncheck it for more accurate separation, at the risk of less intuitive stacking
Use Per-IP Data – Creates a subnet graph by aggregating IP-graph data for every IP in a block/group. On large subnets, this can be very resource-intensive. Only use if the subnet isn’t explicitly defined in the IP Zone, but is part of a larger defined subnet with IP Graphing enabled

41.3. IP Accounting

You can generate IP accounting reports only for IP addresses, blocks, or groups explicitly defined in your IP Zone(s), or belonging to a subnet with IP Accounting enabled.

Decoders – Choose which decoders interest you. New decoders can be defined in General Settings » Custom Decoders and enabled in General Settings » Graphs & Storage
Data UnitBits, Bits/s, Bytes, Bytes/s, Packets, or Packets/s
Report IntervalDaily, Weekly, Monthly, or Yearly. Daily is the finest accuracy, so a narrower time range still returns the whole day’s accounting data
DirectionAll shows both directions; Inbound and Outbound show a single direction
Group Sensor Interfaces – Generates a single traffic accounting report for multiple Sensor Interfaces
Show IPs – Check to see each IP in the selected block or group in the accounting report. Enabling this also activates the option below
Use Per-IP Data – Aggregates IP accounting data for every IP in the block/group. Can be very resource-intensive on large subnets. Only use when the block/group itself isn’t explicitly defined in the IP Zone but is part of a larger subnet with IP Accounting enabled
Raw Values – Shows values without metric prefixes (e.g., 1000000 instead of 1M)

41.4. Anomaly Overview

Generates a report with trends and summaries of traffic anomalies for the selected IP address, block, or group.

41.5. Profile Graphs

Displays traffic profiling graphs for the chosen IP block or host. Profiling can be turned off through the Profile Anomalies setting in General Settings » Anomaly Detection. The Sensor only creates profile graphs for IP blocks/hosts that have profiling rules defined in the IP Zone, either directly or through a Profiling Template.

Data UnitPkts/s or Bits/s
DirectionReceives or Sends
Decoder – Select the decoder of interest
Size – Choose a preset dimension or enter a custom size as “<X> x <Y>” where <X> and <Y> are the horizontal/vertical pixel counts
Title – Enter your own text as the title, or select Auto for an automatically generated title or None for no title
Refresh – Press Generate to build the graphs, or select an automatic refresh interval

Profile graphs cannot currently be printed, exported, or emailed.

41.6. Flow Records

Lists and filters flow data for the selected Flow Sensor Interfaces and IP block/host/group. These options are described in Reports » Tools » Flows. Visible only if at least one Flow Sensor is active and, for guest accounts, the role grants access to the Flows tool.

41.7. Flow Tops

Generates tops from the flow data gathered by the selected Flow Sensor Interfaces for the chosen IP block/host/group. The options are explained in Reports » Tools » Flows. Visible only if at least one Flow Sensor is active and, for guest accounts, the role grants access to the Flows tool.

41.8. Flow Graphs

Builds interactive charts from the flow data gathered by the selected Flow Sensor Interfaces for the chosen IP block/host/group. It requires the Flow Sensor to store flow data in ClickHouse. The options are explained in Reports » Tools » Flows. Visible only if at least one Flow Sensor is active and, for guest accounts, the role grants access to the Flows tool.