Skip to main content

View Traffic Filtering (IDS/IPS) Metrics

Abstract

View tenant-wide Cyber Shield Traffic Filtering event metrics from Shield — monitor observed and blocked traffic events with Total Events, Average, Min, and Max counters; filter by period and event type; break down by user; and export all events to CSV.

Overview

Use Traffic Filtering metrics to review tenant-wide Cyber Shield events where tunneled traffic matched a threat signature.

Traffic Filtering uses an Intrusion Detection System (IDS) to monitor matching traffic and an Intrusion Prevention System (IPS) to block matching traffic according to your Shield Policy configuration.

On Shield → Metrics, use the Filtering Type and Events controls to switch between monitored and blocked Traffic Filtering activity. Metrics shows event totals, trends, threat categories, User breakdowns, and CSV export options for the selected period.

Available Period options are plan-dependent.

For an overview of the Metrics page and its common controls, refer to View Event Metrics.

View monitored Traffic Filtering events

Use this view to review traffic that matched Cyber Shield threat signatures, regardless of whether the traffic was ultimately blocked.

  1. Navigate to Shield → Metrics.

  2. For Filtering Type, select Traffic.

  3. For Events, select Monitored.

  4. Select the desired Period.

  5. Review Total Events, Average, Min, and Max.

  6. Review the event chart to identify changes in monitored Traffic Filtering activity over the selected period.

  7. Review the threat categories below the chart.

    • The category breakdown shows the number and percentage of matching events associated with each threat category.

    Note

    When you change the period or filtering controls, Metrics displays a loading state while CloudConnexa retrieves the data. If no monitored Traffic Filtering events match your selections, Metrics displays an empty state.

View blocked Traffic Filtering events

Use this view to review traffic that Cyber Shield blocked after matching configured Traffic Filtering protections.

  1. Navigate to Shield → Metrics.

  2. For Filtering Type, select Traffic.

  3. For Events, select Blocked.

  4. Select the desired Period.

  5. Review Total Events, Average, Min, and Max.

  6. Review the event chart to identify changes in blocked Traffic Filtering activity over the selected period.

  7. Review the threat categories below the chart.

    • The category breakdown shows the number and percentage of matching events associated with each threat category.

For information about threat priorities and categories, refer to Traffic Filtering.

View events by category

By default, Metrics displays matching events by category.

  1. Select the Period, Filtering Type, and Events you want to review.

  2. Review the categories below the event chart.

  3. For each category, review:

    • The number of matching events.

    • The percentage of matching events represented by the category.

  4. Select Category to change the sort order.

Break down Traffic Filtering events by User

Use Breakdown → Users to identify the Users associated with the selected events.

  1. Select the Period, Filtering Type, and Events you want to review.

  2. Select Breakdown.

  3. Select Users.

  4. Review the events associated with each User.

    • The User breakdown reflects your current Period, Filtering Type, and Events selections.

Export all Traffic Filtering events to CSV

Use Export All Events to CSV to request detailed event data for the current Metrics view.

  1. Select the Period, Filtering Type, and Events you want to export.

  2. Select the desired Breakdown or drill-down level, if applicable.

  3. Select Export All Events to CSV.

    • CloudConnexa displays a confirmation that it will send the report to the Owner's email address shortly. The export reflects the active filters, selected period, and current drill-down level.

  4. Open the report email.

  5. Select Download Report.

    • CloudConnexa opens the Administration portal and starts the report download.

For details about the downloaded CSV report, the three-day download link, and expired or invalid links, refer to Export CSVs.