for multiple Web Appliances, the values shown are averages of all active Web Appliances (averages
do not include Web Appliances without data).
The available search parameters vary from one report to another. See “Modifying Reports” for a
description of each parameter.
5.1.3 Traffic & Performance: Throughput
By default, a bar graph and data table of the volume of data, in the form of megabits per second,
that the Web Appliance has handled hourly for the current day since midnight. If you view this
report for multiple Web Appliances, the values shown are totals of all Web Appliances.
The available search parameters vary from one report to another. See “Modifying Reports” for a
description of each parameter.
5.1.4 Users: Virus Downloaders
By default, a pie chart of the top five virus downloaders, plus all others, each shown as a
percentage of the total number of viruses downloaded today since midnight. The data table shows
the following:
■
full list of users who downloaded viruses during the reporting period. If your Web Appliance
is configured to access a single-domain Active Directory server, only the username of each
user is displayed; if the Web Appliance is configured to access the global catalog of a
multidomain Active Directory forest, users are displayed in the form "domain\username".
Usernames for eDirectory are specified in the form
user.context
.
■
IP addresses to which the viruses were downloaded.
■
Count of the viruses downloaded.
■
The top five viruses downloaded (maximum) for each user.
Click on a username to view a Search > By User of all URLs blocked due to viruses.
The available search parameters vary from one report to another. See “Modifying Reports” for a
description of each parameter.
5.1.5 Users: Sandstorm Users
By default, a pie chart of the top five users who have had the most files referred to Sophos
Sandstorm, plus all others, each shown as a percentage of the total number of files flagged as
suspicious today since midnight. The data table shows the following:
■
Username: Full list of users with files referred to Sandstorm during the reporting period. If
your Web Appliance is configured to access a single-domain Active Directory server, only the
username of each user is displayed; if the Web Appliance is configured to access the global
catalog of a multidomain Active Directory forest, users are displayed in the form
"domain\username". Usernames for eDirectory are specified in the form
user.context
.
■
Originating IP: The originating IP of the user.
■
Clean: files that have been analyzed and that exhibit no malicious behavior.
■
Malicious: files that Sophos Sandstorm has determined are malicious.
■
Unsuccessful: files that could not be analyzed.
158 | Reports | Sophos Web Appliance