Type | Count |
Total entries processed | 18995 |
Entries matched on | 299 |
Inbound traffic | 18952 |
Outbound traffic | 8 |
Control Messages | 35 |
Entries Ignored | 25 |
Alert Entries | 2 |
Attack Types | 0 |
Unique Attack URLs | 0 |
Encrypted/Decrypted Entries | 4 |
Unknown Entries | 0 |
Alert Entries
Crypt/Decrypt Entries
Highlighted Entries
Source Address | Destination Address | Service | Count | Rule |
fwmain01.foo.com(http) | dhcp-100-101-167-223.dhcp.foo.com | tcp(1167) | 8 | 4 |
webfoogen1.foo.com(telnet) | zeus.lab.foo.com | tcp(1573) | 33 | 4 |
webfoogen1.foo.com(telnet) | devel.lab.foo.com | tcp(35338) | 9 | 4 |
webfoogen1.foo.com(telnet) | devel.lab.foo.com | tcp(38530) | 41 | 4 |
webfoogen1.foo.com(telnet) | devel.lab.foo.com | tcp(38567) | 42 | 4 |
gwt.lab.foo.com(22619) | corelinkmain01.foo.com | tcp(45) | 1 | 3 |
webfoogen1.foo.com(telnet) | devel.lab.foo.com | tcp(54924) | 7 | 4 |
dhcp-100-101-167-223.dhcp.foo.com(1234) | fwmain01.foo.com | tcp(FW1_mgmt) | 1 | 4 |
corelinkmain01.foo.com(11081) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11066) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
fwrtrmain01.foo.com(11046) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11061) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11060) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11050) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11075) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11053) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11051) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11082) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11049) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11000) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11044) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11073) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11055) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11045) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11065) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11041) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11079) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11047) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11059) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11048) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11056) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11064) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
fwrtrmain01.foo.com(11047) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11052) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11084) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11078) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11062) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11068) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11074) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11063) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11054) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
fwrtrmain01.foo.com(11000) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11067) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
fwrtrmain01.foo.com(11048) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11077) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11083) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11072) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11057) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11001) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11069) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11043) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
fwrtrmain01.foo.com(11050) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11070) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11042) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11046) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11058) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
fwrtrmain01.foo.com(11049) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
corelinkmain01.foo.com(11071) | apollo.foo.com | tcp(TACACSplus) | 1 | 4 |
webfoogen1.foo.com(1023) | apollo.foo.com | tcp(login) | 1 | 4 |
devel.lab.foo.com(1019) | webfoogen1.foo.com | tcp(login) | 1 | 4 |
devel.lab.foo.com(1021) | webfoogen1.foo.com | tcp(login) | 1 | 4 |
192.1.28.252(1023) | webfoogen1.foo.com | tcp(login) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(3167) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1325) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1316) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1322) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(3194) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1297) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1272) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1919) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1300) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(3178) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(3170) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1279) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(1916) | webwebmain01.foo.com | tcp(nbsession) | 1 | 4 |
gwt.lab.foo.com(1023) | fwfoomain01.foo.com | tcp(shell) | 1 | 3 |
dhcp-100-101-162-201.dhcp.foo.com(990) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5300) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(917) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(910) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(939) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5212) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5303) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5209) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(937) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5298) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5305) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5306) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(971) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(997) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5206) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5301) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5207) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5297) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5302) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5304) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5205) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(908) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(921) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(951) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5208) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5308) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(954) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5307) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(5299) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
dhcp-100-101-162-201.dhcp.foo.com(962) | webwebmain01.foo.com | tcp(sunrpc) | 1 | 4 |
test.lab.foo.com(6863) | fwfoomain01-2 | tcp(tcpmux) | 1 | 3 |
test.lab.foo.com(6862) | fwfoomain01.foo.com | tcp(tcpmux) | 1 | 3 |
corelinkmain01.foo.com(64514) | rtnw.foo.com | tcp(telnet) | 1 | 4 |
dhcp-100-101-167-233.dhcp.foo.com.au(1586) | fwfoomain01.foo.com.au | tcp(telnet) | 1 | 3 |
webfoogen1.foo.com(32819) | apollo.foo.com | tcp(telnet) | 1 | 4 |
fwrtrmain01.foo.com(63490) | rtnw.foo.com | tcp(telnet) | 1 | 4 |
gwt.lab.foo.com(22620) | fwfoomain01.foo.com | tcp(telnet) | 1 | 3 |
dhcp-100-101-167-233.dhcp.foo.com(1487) | fwfoomain01.foo.com | tcp(telnet) | 1 | 3 |
gwt.lab.foo.com(22620) | fwfoomain01.foo.com | tcp(telnet) | 1 | 3 |
dhcp-100-101-167-233.dhcp.foo.com(1588) | fwfoomain01.foo.com | tcp(telnet) | 1 | 3 |
fwrtrmain01.foo.com(12803) | 192.1.1.13 | tcp(telnet) | 1 | 4 |
corelinkmain01.foo.com(11266) | 192.1.1.13 | tcp(telnet) | 1 | 4 |
fwmain01.foo.com(1031) | rtnw.foo.com | tcp(telnet) | 1 | 4 |
gwt.lab.foo.com(22659) | fwfoomain01.foo.com | tcp(telnet) | 2 | 3 |
gwt.lab.foo.com(22657) | fwfoomain01.foo.com | tcp(telnet) | 1 | 3 |
dhcp-100-101-167-233.dhcp.foo.com(177) | fwmain01.foo.com | udp(177) | 2 | 4 |
gwt.lab.foo.com(65446) | fwfoomain01.foo.com | udp(33441) | 1 | 3 |
gwt.lab.foo.com(65446) | fwfoomain01.foo.com | udp(33442) | 1 | 3 |
gwt.lab.foo.com(65446) | fwfoomain01.foo.com | udp(33443) | 1 | 3 |
dhcp-100-101-167-233.dhcp.foo.com(nbname) | fwfoomain01-2 | udp(nbname) | 1 | 4 |
mlink.foo.co.uk(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 1 | 3 |
mlink.foo.co.uk(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 2 | 3 |
fwrtrmain01.foo.com(ntp-udp) | ns4.foo.net | udp(ntp-udp) | 1 | 3 |
fwrtrmain01.foo.com(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 5 | 3 |
mlink.foo.co.uk(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 4 | 3 |
mlink.foo.co.uk(ntp-udp) | ns4.foo.net | udp(ntp-udp) | 2 | 3 |
fwrtrmain01.foo.com(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 2 | 3 |
fwrtrmain01.foo.com(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 15 | 4 |
mlink.foo.co.uk(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 2 | 3 |
fwrtrmain01.foo.com(ntp-udp) | ns4.foo.com | udp(ntp-udp) | 3 | 3 |
Service | Count | Of Entries |
smtp | 25 | 7.72% |