View Cyber Shield Event Metrics
View tenant-wide Cyber Shield Domain Filtering event metrics from Shield — monitor observed and blocked domain events with Total Events, Average, Min, and Max counters; filter by period and event type; break down by user; and export all events to CSV.
These metrics include the Average Volume, Maximum Volume, and Minimum Volume of Observed or Blocked Domains events for a selected period (24 hours, 7 days, 30 days). You may drill down to a more detailed report by category from the 7-day and 30-day ranges.
Overview
Use Metrics to inspect blocked and monitored Domain Filtering and Traffic Filtering events tenant-wide. Metrics provide event totals and trends for the selected period and let you analyze which categories and users generated the events.
Use the Filtering Type and Events controls to switch between Domain and Traffic events and between monitored and blocked activity. You can also change the period, review event statistics, use Breakdown to analyze the data, and select Export All Events to CSV to export detailed event data.
The available period options are plan-dependent.
This topic describes the Metrics page and Domain Filtering metrics. For details about Traffic Filtering events, refer to View Traffic Filtering (IDS/IPS) Metrics.
Open Cyber Shield Metrics
Select Shield → Metrics.
Tip
You can also open Metrics from the Top 10 Dashboard on Shield → Overview when you select View All below the category list.
For more information about the Top 10 Dashboard, refer to Interact With the Top 10 Dashboard.
Select the event metrics to view
Use the controls at the top of the Metrics page to select the events you want to analyze.
Control | Options | Description |
|---|---|---|
Period | Varies by plan | Sets the period for the displayed metrics. Available options are plan-dependent. |
Filtering Type | Domain, Traffic | Selects Domain Filtering or Traffic Filtering events. |
Events | Monitored, Blocked | Selects whether to display monitored or blocked events. |
The counters, chart, and event breakdown update to reflect your selections.
For Domain Filtering, select:
Domain → Monitored to view monitored domain activity.
Domain → Blocked to view blocked domains.
Note
Monitored events are events Cyber Shield detects and records. Blocked events are events Cyber Shield prevented based on your filtering configuration.
Review event totals
Use the event counters to summarize activity for the current Metrics view.
Select the Period, Filtering Type, and Events you want to review.
Review the event counters:
Total Events: Total number of events matching the selected period, Filtering Type, and Events settings.
Average: Average number of matching events across the time intervals displayed in the chart.
Min: Lowest number of matching events in a displayed time interval.
Max: Highest number of matching events in a displayed time interval.
The counters update when you change the Period, Filtering Type, or Events.
View event trends
Use the chart to review how Cyber Shield event volume changes over the selected period.
Select a Period.
For Filtering Type, select Domain or Traffic.
For Events, select Monitored or Blocked.
Review Total Events, Average, Min, and Max for the selected events.
Review the chart to identify changes in event volume over the selected period.
The chart title reflects your selections, such as Monitored Domain Events or Blocked Domain Events.
Note
When you change the period or filtering controls, Metrics displays a loading state while CloudConnexa retrieves the data. If no events match your selections, Metrics displays an empty state. Change the Period, Filtering Type, or Events selection to view other activity.
View events by category
By default, Metrics displays matching events by category.
Select the Period, Filtering Type, and Events you want to review.
Review the categories below the event chart.
For each category, review:
The number of matching events.
The percentage of matching events represented by the category.
Select Category to change the sort order.
For Domain Filtering, the categories classify the observed domains or blocked domains represented by the selected events.
Break down events by User
Use Breakdown → Users to identify the Users associated with the selected events.
Select the Period, Filtering Type, and Events you want to review.
Select Breakdown.
Select Users.
Review the events associated with each User.
The User breakdown reflects your current Period, Filtering Type, and Events selections.
Export all events to CSV
Use Export All Events to CSV to request detailed event data for the current Metrics view.
Select the Period, Filtering Type, and Events you want to export.
Select the desired Breakdown or drill-down level, if applicable.
Select Export All Events to CSV.
CloudConnexa displays a confirmation that it will send the report to the Owner's email address shortly. The export reflects the active filters, selected period, and current drill-down level.
Open the report email.
Select Download Report.
CloudConnexa opens the Administration portal and starts the report download.
For details about the downloaded CSV report, the three-day download link, and expired or invalid links, refer to Export CSVs.