Barracuda Analytics

Adding the Barracuda Dashboard

  1. Go to Settings >> Knowledge Base >> Dashboards.

  2. Select VENDOR DASHBOARD from the drop-down.

  3. Click the Use icon from the Actions column.

Dashboard

Adding the Barracuda Dashboard

  1. Click Choose Repos.

Barracuda Ask Repos Panel

Selecting Repos

  1. Select the repo and click Done.

Barracuda Ask Repos Panel

Selecting Repos

  1. Click Ok.

You can find the Barracuda dashboards under Dashboard.

Barracuda Dashboard

Barracuda Dashboard

Barracuda Widgets

Widgets available in LP_Barracuda Web Application Firewall provide:

Widget

Description

Attack Count

The count of attacks such as the DDOS attack.

Attack Timetrend

A time trend of attacks detected by the Barracuda Web Application Firewall.

Top 10 Attack Events

An overview of the top 10 attack events detected by the Barracuda Web Application Firewall.

Top Distinct Attacks by Source Locations

An overview of the top distinct attacks based on source country, action, and destination address.

Total Attackers

The count of total attackers based on source address.

Top Actions Taken on Traffic

An overview of the top actions taken on traffic.

Top 10 Errors from Client

An overview of the top 10 fault (error) codes from clients, such as Invalid Request (status code 400), Authentication Failed (401), Not Found (status code 404), Method Not Allowed (status code 405), and Invalid Post Data (status code 415).

Top 10 Protocols

An overview of the top 10 protocols.

Injection Attack Details

A detailed overview of the injection attack based on attack and actions.

DOS Attack Details

A detailed overview of the DOS attack details based on attack and actions.

Top 10 Users in Attack Events

An overview of the top 10 remote or local users whose involvement was detected during the attack events.

Attack Details

A detailed overview of the attack events by source address, source country, attack type, destination address, destination country, request method, URL, rule type, and actions.

Widgets available in LP_Barracuda SV Firewalll provide:

Widget

Description

Top 10 Action

An overview of the top 10 actions performed by users detected by the Barracuda Firewall.

Top 10 Mail Destinations Domain

An overview of the top 10 destination addresses or domains where mails were sent.

Top 10 Source Address

An overview of the top 10 source addresses.

Top 10 Mail Sender

An overview of the top 10 email senders.

Top 10 Mail Receiver

An overview of the top 10 email recipients.

User Login - List

A detailed overview of user logins by login timestamp, username, and actions.

Time trend of Action

A time trend of the Barracuda Firewall actions.

Top 10 Destination Address

An overview of the top 10 destination addresses.

Message Category - RECV and SCAN services

An overview of the Barracuda RECV and SCAN services with their action code, such as Allowed Message, Aborted Message, Blocked Message, Quarantined Message, and so on.

Message Category - SEND services

An overview of the Barracuda SEND services, such as Delivered Message, Rejected Message, Deferred Message, and Expired Message.

Top 15 Event Category by Reason Code

An overview of the top 15 Barracuda event categories by reason code, such as Virus, Banned Attachment, or RBL Match.

Top 10 Hosts in Barracuda Blocklist Category

An overview of the top 10 hosts in the block list category.

Top 10 Senders in Barracuda Blocklist Category

An overview of the top 10 senders in the block list category.

Top 10 Receivers in Barracuda Blocklist Category

An overview of the top 10 receivers in the blocklist category.

Top 10 Hosts in Virus Category

An overview of the top 10 hosts categorized as Virus of Barracuda RECV and SCAN services.

Top 10 Senders in Virus Category

An overview of the top 10 senders categorized as Virus of Barracuda RECV and SCAN services.

Top 10 Receivers in Virus Category

An overview of the top 10 receivers categorized as Virus of Barracuda RECV and SCAN services.

Top 10 Receivers in Banned Attachment Category

An overview of the top 10 receivers in the Band Attachment category of Barracuda RECV and SCAN services.

Top 10 Senders in Banned Attachment Category

An overview of the top 10 senders in the Band Attachment category of Barracuda RECV and SCAN services.

Top 10 hosts in Banned Attachment Category

An overview of the top 10 hosts in the Band Attachment category of Barracuda RECV and SCAN services.

Top 10 host in Spam Fingerprint Found Category

An overview of the top 10 hosts in the Spam Fingerprint Found category of Barracuda RECV and SCAN services.

Top 10 Sender in Spam Fingerprint Found Category

An overview of the top 10 senders in the Spam Fingerprint Found category of Barracuda RECV and SCAN services.

Top 10 receiver in Spam Fingerprint Found Category

An overview of the top 10 receivers in the Spam Fingerprint Found category of Barracuda RECV and SCAN services.

Widgets available in LP_Barracuda Web Filter provide:

Widget

Description

Barracuda Web Filter Details - List

A detailed list of Barracuda Web Filters activities based on timestamp, source address, destination address, URL, action, reason, content type (HTML or jpeg), data size, matched part, and category.

Top 10 Source Address

An overview of the top 10 source addresses.

Top 10 Destination Address

An overview of the top 10 destination addresses.

Top 10 Action with Reason

An overview of the top 10 actions performed by Barracuda Web Filter along with the reasons for which the actions were taken. For example, device scanned as a threat is detected.

URL Details - List

A detailed list of the frequently visited URLs based on action, reason, matched part, and category.

Top Content Type - List

A detailed list of the top website contents filtered by Barracuda Web Filters.

Top Matched Part - List

A detailed list of the top regular expressions, domain names, or keywords that matched to a URL.

Top Matched Category - List

A detailed list of the top built-in or customized web content categories that matched with your regular expressions, domain names, or keywords.

Barracuda Labels

Labels available in LP_Barracuda NG Firewall are:

Labels

Description

Allow

Events with the Allow or LocalAllow action.

Deny

Events with the Deny or LocalDeny action.

Drop

Events with the Drop and LocalDrop action.

Detect

Events with the Detect or LocalDetect action.

ARP

Events with the ARP action.

Normal, Operation

Events with the Normal Operation message.

Balance, Session, Idle, Timeout

Events with the Balanced Session Idle Timeout message.

Block, Rule

Events with the Block by Rule message.

Connection, Rese, Source

Events with the Connection Reset by Source message.

Session, Idle, Timeout

Events with the Session Idle Timeout message.

Connection, Reset

Events with the Connection Reset by Destination message.

Acknowledge, Timeout

Events with the Last ACK Timeout message.

TCP,Packet, Not, Active, Session

Events with the TCP Packet Belongs to no Active Session message.

ARP, Duplicate, MAC

Events with the ARP reply duplicate and MAC differs message.

ICMP, Packet, Ignore

Events with the ICMP Packet is Ignored message.

Connection, Timeout

Events with the Connect Timeout message.

Timeout

Events with the Unreachable Timeout message.

Block, Broadcast

Events with the Block Broadcast message.

Timeout

Events with the Halfside Close Timeout message.

Application, Control

Events with the Application Control message.

Detect, Not, Allow, Port

Events with the Unallowed Port Protcol Detected message.

Reverse, Routing, Interface, Mismatch

Events with the Reverse Routing Interface Mismatch message.

Accept, Timeout

Events with the Accept Timeout message.

TCP, Header, Invalid

Events with the TCP Header has an Invalid SEQ Number message.

IPS, Warning

Events with the IPS Warning message.

Drop, Not, Allow, Port, Detect

Events with the Drop due to Unallowed Port Protocol message.

MAC, Address, Change

Events with the MAC Address Change message.

Local, Socket, Not, Present

Events with the No Local Socket Present message.

Policy, Block, URL, Category

Events with the URL Category Blocked by Policy message.

Block, Not, Rule, Match

Events with the Block no Rule Match message.

Not, Active, Session, ICMP, Packet

Events with the ICMP Packet Belongs to no Active Session message.

TCP, Header, Invalid

Events with the TCP Header has an Invalid ACK Number message.

Internal, SSL, Error

Events with the Internal SSL Error message.

Invalid, Synchronization, Establish, TCP, Session

Events with the Invalid SYN for Established TCP Session message.

Drop, TCP, RST

Events with the Drop guessed TCP RST message.

IPS, Drop, Log

Events with the IPS Drop Log message.

IPS, Alert

Events with the IPS Alert message.

Block, Local, Loop

Events with the Block Local Loop message.

Terminate, Content

Events with the Terminated due to content message.

IP, Header, Incomplete

Events with the IP Header is Incomplete message.

Request, IPS, Policy, Terminate

Events with the IPS Policy Requested Termination message.

Duplicate, IP, Detect, Match

Events with the Duplicate IP Detection Matched message.

TCP, Header, Incomplete

Events with the TCP Header is Incomplete message.

TCP, Header, Checksum, Invalid

Events with the TCP Header Checksum is Invalid message.

TF-Sync

Events with the TF-Sync message.

Block

Events with the Block or LocalBlock action.

Remove

Events with the Remove or LocalRemove action.

Fail

Events with the Remove or LocalRemove action.

Labels available in LP_Barracuda Web Filter are:

Labels

Description

Allow

Events with the ALLOWED action.

Block

Events with the BLOCKED action.

Detect

Events with the DETECTED action.

Clean

Events with the CLEAN reason.

Virus

Events with the VIRUS reason.

Skyware

Events with the SPYWARE reason.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support