{"id":20107,"date":"2023-12-07T11:37:58","date_gmt":"2023-12-07T11:37:58","guid":{"rendered":"https:\/\/exa.net.uk\/?p=20107"},"modified":"2024-02-15T12:24:14","modified_gmt":"2024-02-15T12:24:14","slug":"surfprotect-reporting-tools","status":"publish","type":"post","link":"https:\/\/edit.exa.net.uk\/help\/surfprotect\/using-surfprotect\/surfprotect-reporting-tools\/","title":{"rendered":"SurfProtect Reporting tools"},"content":{"rendered":"\t\t
These tools allow for you to get an overview of the web activity that your SurfProtect service has filtered.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
Website Analytics provides an overview of all web requests made within a queried time period, providing information about when it happened, who did it, what they did and what the filtering decision was.<\/p>
This is broken down into a number of easier to digest sections:<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
These options allow you to filter the Analytics results to a more limited set of results.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
The first three of these options are broad, quick filters which can be applied to the displayed results. By default, the \u2018All\u2019 filter is selected, which shows every request that has been filtered. Switching to the \u2018Permit\u2019 or \u2018Reject\u2019 filters shows only results which either have a Permitted or Rejected status.<\/p>
The final option, the search icon, allows you to filter results in a much more granular way.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
This allows you to filter results down to specific time periods, internal or external ips, users, etc. The \u2018All\u2019, \u2018Permit\u2019 and \u2018Reject\u2019 options can be enabled, which will limit the results further to these specific statuses.<\/p>
When these more advanced filters have been set, you can see them listed beneath the activity graph.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
This graph shows the rate of filtered requests over the queried time period. Requests are grouped into five-minute intervals so that the volume of traffic being generated over these time periods can be more easily visualised at high resolution.<\/p>
The data in this graph shows permitted and rejected requests independently, however currently it is not possible to filter these results further and will not update to match the filters that are set.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
The final section of this page is the Activity logs themselves, which show data about every filtered web request that has been handled by your SurfProtect service. These logs are split into four tabs of data:<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
Activities: <\/strong>This is the most granular set of logs, showing every request in the order it happened during the queried time period, limited to the query filters set by the user.<\/p> Unique activities:<\/strong> This is an alternative view of the Activities logs. In this view you can see all of the unique activities, how many times each has happened, when it first occurred and when it last occurred within the queried time period. Some information is not shown here, like usernames, as this view is focused on the number of occurrences rather than the specific logs.<\/p> Searches: <\/strong>This is a view of all the requests seen by the filtering where an identifiable search query was found, again limited to queried time period and query filters.<\/p> Unique searches: <\/strong>This is an alternative view of Search logs. In this view you can see all of the unique searches which were performed, how many times each has happened, when it first occurred and when it last occurred within the queried time period. Some information is not shown here, like usernames as this view is focused on the number of occurrences rather than the specific logs.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t SurfProtect Real-time Alerts is a monitoring system that looks for specific types of behaviour when users are web browsing. When a set of requests within a given timeframe are identified as something that should be reported upon, an incident is created with those requests as events within it.<\/p> The interface on the panel allows a user to view and manage these incidents as they are reported.<\/p><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t Due to the sensitive nature of the data available, specific access rights must be granted to access the panel. The ability to access Real-time Alerts can only be granted by an existing user of that account.<\/p> For example, if a user needs to be able to view your Real-time Alerts then the Admin user can either grant an existing user access or create a new user with access.<\/p> Once logged into the self administration panel, existing user logins for the account can be managed from the user menu in the top right hand corner.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t Selecting the \u2018Manage logins\u2019 menu option will navigate to show the list of all user logins for the account. This page then allows for the creating and updating of those users.<\/p><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t To create a new user account, and grant Real-time Alerts access, simply click the plus button in the top right corner of the Login Management table. This will open the user creation dialogue, which takes the following values:<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t Customer:<\/strong> The customer you would like to assign the new user to.<\/p> Real time alert user:<\/strong> A toggle that allows the user to access real time alerts data for the account.<\/p> Application Access:<\/strong> The applications the user is able to access. This will allow the user to access the full panel, or only the SurfProtect panel.<\/p> Real name:<\/strong> The full real name of the user.<\/p> Username:\u00a0<\/strong>The chosen username for the user. This will be used to log into the application, and will be displayed on the panel after login.<\/p> Password: <\/strong>Password for the new user, which must at least meet the medium strength requirements to be created.<\/p> Comment:\u00a0<\/strong>This section allows you to add additional comments. This is not required.\u00a0<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t For existing users, toggling ‘Real time alert user’ on the Login Management table will prompt to either enable or disable the ability for the user to access Real-time Alerts data on the panel.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t This is the area where designated contacts for Real-time Alerts are setup and managed. A contact is defined as someone who should receive notifications about incidents (e.g. Safeguarding Officer\/Lead). Each contact is made up of three parts:<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t Contact information: <\/strong>First name and last name<\/p> Contact method:<\/strong> Email is the only available contact method currently. In future alternative methods of contact may be developed<\/p> Locations managed: <\/strong>Identification of all Locations the User is to receive alerts for<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t Adding a contact who does not already have a user profile will only generate the alert emails and will not grant access to the Real-time Alert area within the panel.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t An incident is a one or more online activities (\u201cevents\u201d) that are deemed to be potentially harmful. There are two types of incident, category and keyword. The number of events required to trigger an incident depends on the specific category or keyword.<\/p><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div><\/div>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\tReal-time Alerts<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
Reports<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
\nManaging logins<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
Managing contacts<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
Incidents<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
Category<\/h4>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t