010-68421378
sales@cogitosoft.com
Categories
AddFlow  AmCharts JavaScript Stock Chart AmCharts 4: Charts Aspose.Total for Java Altova SchemaAgent Altova DatabaseSpy Altova MobileTogether Altova UModel  Altova MapForce Altova MapForce Server Altova Authentic Aspose.Total for .NET Altova RaptorXML Server ComponentOne Ultimate Chart FX for SharePoint Chart FX CodeCharge Studio ComponentOne Enterprise combit Report Server Combit List & Label 22 Controls for Visual C++ MFC Chart Pro for Visual C ++ MFC DbVisualizer version 12.1 DemoCharge DXperience Subscription .NET DevExpress Universal Subscription Essential Studio for ASP.NET MVC FusionCharts Suite XT FusionCharts for Flex  FusionExport V2.0 GrapeCity TX Text Control .NET for WPF GrapeCity Spread Studio Highcharts Gantt Highcharts 10.0 版 HelpNDoc Infragistics Ultimate  ImageKit9 ActiveX ImageKit.NET JetBrains--Fleet JetBrains-DataSpell JetBrains--DataGrip jQuery EasyUI jChart FX Plus OPC DA .NET Server Toolkit  OSS ASN.1/C Oxygen XML Author  OSS 4G NAS/C, C++ Encoder Decoder Library OSS ASN.1 Tools for C with 4G S1/X2 OSS ASN.1/C# OSS ASN.1/JAVA OSS ASN.1/C++ OPC HDA .NET Server Toolkit OPC DA .Net Client Development Component PowerBuilder redgate NET Developer Bundle Report Control for Visual C++ MFC  Sencha Test SPC Control Chart Tools for .Net Stimulsoft Reports.PHP Stimulsoft Reports.JS Stimulsoft Reports.Java Stimulsoft Reports. Ultimate Stimulsoft Reports.Wpf Stimulsoft Reports.Silverlight SlickEdit Source Insight Software Verify .Net Coverage Validator Toolkit Pro for VisualC++MFC TeeChart .NET Telerik DevCraft Complete Altova XMLSpy Zend Server

Fastvue Reporter for Palo Alto Networks

Simple Internet Usage Reporting for Palo Alto Networks.

 

Palo Alto Networks Reporting Simplified!

You don’t need to be a log analysis expert to understand Fastvue Reports. Designed for HR, Teachers, Department Managers and IT.

 

 

“The best part for me is that once I setup the reports and who they go to, I am out of the loop totally. The department manager can parse through the report, run more detailed reports, and take action without involving me at all as a net admin. Fastvue Site Clean made it even easier for the managers to understand (How do you explain what a CDN is to the accounting manager?).”

Andrew Reynolds, Frasca

 

“Fastvue Reporter makes reporting against Internet usage very easy and friendly to use. Non-technical staff/managers can now view reports and get a meaningful and clear picture of what is happening.”

David Sewell, Waimakariri District Council

 

Live Dashboards

Fastvue Reporter is always ready to show you what is happening on your network right now. Real-time dashboards focus on the trifecta of network concerns: Bandwidth, Productivity and Security.

 

 

Don’t Trust Your Firewall’s Internet Usage Reports

Internet Reports produced by web gateways such as Palo Alto Networks do not distinguish between the web sites people intentionally access, and the web sites that are automatically accessed behind the scenes.

 

Fastvue Site Clean makes the log data from your firewall reflect real Internet usage activity. It removes images, scripts, fonts, ads, and other background traffic so you can send meaningful Internet usage reports and alerts, to the right person.

 

 

Simple Report Scheduling

Managing employee productivity is a job for Department Managers or HR. Get web activity reporting off your desk and into the hands of the people that need it! Easily filter reports by Departments, Security GroupsOffices, or Subnets and automatically send them to the right person each day, week or month.

 

 

Detailed Investigations

Fastvue’s innovative Activity Reports not only include full activity details such as timestamps and full URLs, but they intuitively group them into browsing sessions with green bars showing exactly when browsing started and stopped. A real time saver compared with trawling through logs.

 

 

Intelligent Alerts

Send instant alerts to the right people as soon as notable issues occur such as enormous downloads, and unacceptable activity and network threats. All the detail they need, sent straight to their inbox!

 

 

Productivity Reporting

Fastvue Reporter assesses web productivity according to your guidelines to highlight unproductive or unacceptable browsing.

See exactly what is being allowed (or blocked) that shouldn’t be, and adjust your Content Filter policies accordingly.

 

 

“Fastvue Reporter gave us the ability to identify time-wasting traffic and maximize our bandwidth usage for all employees. Such a great granular reporting tool!”

Chris Martel, Spiller's

 

Active Directory Integration

Seamless (zero config) AD integration, enables simple reporting across AD Departments, Offices, Companies and Security Groups.

 

 

Advanced Filtering

Need the flexibility to schedule reports for subnets instead of departments, or ‘monitored’ traffic vs ‘allowed’ traffic, or perhaps drill into a specific MAC address or Source Zone? Fastvue Reporter’s advanced filtering engine narrows down your reports to anything you can dream up!

 

 

Central Reporting Across Multiple Palo Alto Networks Firewalls

Configure all your Palo Alto Networks devices to send Syslog messages to Fastvue Reporter and enjoy a centralized view of your entire network’s web and firewall activity.

 

 

“Fastvue Reporter is fantastic!!! Certainly one of the best software packages I’ve ever come across – does exactly what it needs to do, dead easy to use, and fantastic support from the Fastvue team!”

Gordon Wells, Buckfast Abbey

 

“When our demo ran out I literally felt blind as to what was going on with people surfing, etc. Working with support has been a total pleasure as they’re willing to go above and beyond to make the customer completely satisfied!”

Scott Bentoske, FEC Automation Systems

 

Compare Palo Alto Networks Reporting Options

 

Palo Alto Networks Panorama

  • Designed for Palo Alto Networks Administrators
  • Reports on Palo Alto Networks hardware and network performance
  • Basic information about web usage (top users, domains and categories)

 

Fastvue Reporter for Palo Alto Networks

  • Designed for everyone else concerned about employee internet usage, but also very useful for Palo Alto Networks Administrators.
  • Goes beyond simple log aggregation to provide sensible and useful information around web usage and productivity.
  • Collates data from multiple Palo Alto Networks firewalls into single dashboards, reports and alerts.
  • Productivity Reports utilizing Palo Alto Networks Content Filtering
  • Useful activity reports with full forensic details.
  • Real-time Alerts for any type of traffic or network issue.
  • Integrates with Active Directory for Department/Group reporting (requires user authentication on Palo Alto Networks firewalls)

 

Independent, Honest Reporting

Our reports are not focused on showing you how excellent your Palo Alto Networks firewall is. Our reports may highlight traffic being allowed when it shouldn’t, blocked when it should, mis-categorized websites, ineffective policies and more.

 

Fastvue Reporter gives you the information you need to make your network efficient, productive and secure, getting the most out of your Palo Alto investment.

 

Fastvue Reporter for Palo Alto Networks: Installation and Setup

 

New Installations

 

1. Download and Install

Download Fastvue Reporter for Palo Alto Networks and install on a machine (or virtual machine) that meets our recommended requirements for your network size.

 

Note: Fastvue Reporter is a resource-intensive application by design in order to import data and run reports as fast as possible. We do not recommend installing Fastvue Reporter on a server that provides a critical network service such as a Domain Controller, DNS server, or DFS server. We recommend installing on a dedicated VM (virtual machine) so you can scale the resources appropriately.

 

Supported Operating Systems

Fastvue Reporter is designed for 64 bit Windows Server Operating Systems running Windows Server 2012 R2, or above.

 

The Fastvue Reporter installer will automatically install and configure the required pre-requisites which include .Net 4.6 and IIS (Web Server and Application Server roles). It will also install Open JDK and Elasticsearch in its own self-managed directory.

 

When installing, you will be asked to select a website to install too. If you are installing on a server with existing websites, we recommend creating a new website in IIS and installing to that. You can also choose to install to a sub-folder of an existing website (such as Default Web Site\Fastvue).

 

RAM / CPU Requirements

Network Size

Recommended Server Specification

Less than 500 Users

4 CPUs/Cores, 6 GB RAM

500 – 1000 Users

4 CPUs/Cores, 8 GB RAM

1000 – 3000 Users

8 CPUs/Cores, 12 GB RAM

3000 – 5000 Users

8 CPUs/Cores, 16 GB RAM

5000+ Users

16 CPUs/Cores, 24 GB RAM

* Virtual environments are recommended so you can scale the resources as required.

 

Data Storage Requirements

During installation, you are asked where you want the Data Location to be. The amount of data stored per day will vary depending on the amount of traffic flowing through your Palo Alto Networks firewall.

 

The default data retention policy in Fastvue Reporter is 90 days or 90% of drive space, whichever comes first. If 90% of the drive leaves less than 20 GB free, the retention policy will adjust to allow at least 20 GB for Operating System files if the data path is on the same drive as the OS.

 

These data retention settings can be adjusted in Settings | Data Storage.

We do not advise installing to a network drive due to latency issues affecting the stability of our very frequent read-write operations. For best performance, use a local SSD drive.

 

Do not install to a mapped network drive, or use a mapped network drive as Fastvue Reporter’s data path, as the assigned drive letters will not exist in the system context – only the user context. If you must use a network drive, specify a UNC path such as \\servername-or-ip\fastvue, but keep in mind the performance issues mentioned above, and you will have to configure ‘full’ permissions for the Fastvue Server’s local system account.

 

After one or two days of collecting data, check the size estimates in Settings | Data Storage | Settings to see if you need to make adjustments to the data retention policy or your server’s disk space. These estimates become more accurate as data is imported.

 

Install Fastvue Reporter

To install Fastvue Reporter:

  • Double-click the downloaded setup exe on a machine that meets the above recommendations
  • Proceed through the installation wizard to install the software.  The installation wizard will ask you for:
    • Installation folder (defaults to C:\Program Files\Fastvue\Reporter for Palo Alto). Only application files are installed to this folder. It does not require much disk space.
    • Website and Virtual Directory (defaults to ‘Default Web Site’). If you have other websites installed on your server, it is a good idea to install Fastvue Reporter to a virtual directory such as ‘fastvue’ or ‘paloaltoreports’. Then you can access the site at http://yourserver/fastvue for example and it does not interfere with any other site on your server.
    • Data Location (defaults to C:\ProgramData\Fastvue\Reporter for Palo Alto). This is the location where all imported data, configuration and report files are stored. Specify a location with plenty of disk space.

 

 

2. Configure Palo Alto Networks Firewall’s Syslog Settings

Now that Fastvue Reporter for Palo Alto Networks has been installed, you need to configure your Palo Alto Networks firewalls to send syslog data to the Fastvue server.

 

1. Add the Fastvue Server as a Syslog Server in Palo Alto Networks Firewall

  • On your Palo Alto Networks firewall, select Device | Server Profiles | Syslog.
  • Click Add and enter a Name for the syslog profile such as Fastvue
  • If the firewall has more than one virtual system (vsys), select the Location (vsys or Shared) where this profile is available.
  • Click Add and enter the Fastvue server’s details:
    • Name—Enter a unique name for the server profile such as ‘Fastvue Server’
    • Syslog Server—IP address or fully qualified domain name (FQDN) of the Fastvue server.
    • Transport—Select TCP (UDP also works if required. SSL is not supported at this stage).
    • Port—The port number on which to send syslog messages (default is port 514). You must use the same port number on the Fastvue server when adding your source  (see below). If 514 is already used by another application on the Fastvue server, choose a different port such as 50514.
    • Format—Select BSD (the default).
    • Facility—Select LOG_USER (the default)
  • Click OK to save the server profile.

 

2. Configure a Log Forwarding Profile all logs in Objects | Log forwarding.

  • Select Objects | Log Forwarding, click Add, and enter a Name to identify the profile.

If you want the firewall to automatically assign the profile to new security rules and zones, enter default. If you don’t want a default profile, or you want to override an existing default profile, enter a Name that will help you identify the profile when assigning it to security rules and zones, such as ‘Fastvue Forwarding Profile’.

  • Click Add to add a Log Forwarding Profile Match List
  • Enter URL Logs as the Name, select url as the Log Type and ensure All Logs is selected as the Filter.
  • Check the Syslog checkbox and click Add in the Syslog section. Add the Fastvue syslog server you defined earlier. Click OK.
  • Repeat steps 2 -> 4 for each log type. The main log types Fastvue requires are Traffic, Threat, URL and WildFire.
  • Click OK to save the settings.

 

3. Use the log forwarding profile in your security rules

To trigger log generation and forwarding, your Log Forwarding Profile needs to be assigned to all the security policies you want to log/monitor.

  • Select Policies | Security and select a policy rule such as the rule that allows outbound internet traffic.
  • Select the Actions tab and select the Log Forwarding profile you created above.
  • For Traffic logs, select the Log At Session End checkbox, and click OK.

 

 

3. Set Palo Alto Networks Firewall’s URL Filtering Categories to Block or Alert

To ensure traffic to all URL Categories is logged:

  • Go to Objects | URL Filtering and either edit your existing URL Filtering Profile or configure a new one.
  • Ensure all categories are set to either Block or Alert (or any action other than none).

 

 

4. Enable HTTP Header Logging and Disable “Log Container Page Only”

HTTP Header logging enables the logging of the Referer field which is valuable information for Fastvue’s Site Clean engine.

 

To enable HTTP Header logging, go to Objects | Security Profiles | Settings and enable User-AgentReferer, and X-Forwaded-For checkboxes under HTTP Header.

 

While you are in Objects | Security Profiles | Settings, uncheck the Log Container Page Only checkbox. Fastvue Reporter will automatically group all background web resources into the container page, enabling you to access the full log details if needed.

 

Don’t forget to commit your settings changes!

 

 

5. Add a Source in Fastvue Reporter for Palo Alto Networks

Now that your Palo Alto Networks Firewall is sending Syslog data to the Fastvue Server, you can add the Palo Alto Networks Firewall as a ‘Source’.

 

This can be done on the start page that is presented after installation, or in Settings | Sources | Add Source.

 

If your Palo Alto Networks is sending syslog data on port 514, click into the edit box to add a Source and wait a few seconds. The dropdown will auto-populate with your Palo Alto Networks Firewall. Select your Palo Alto Networks firewall from the dropdown and click Add Source.

If your Palo Alto Networks is not sending syslog data on port 514, manually type the IP address of your Palo Alto Networks Firewall (make sure you use IP of the interface the Fastvue Server is connected to), and enter your port. Then click Add Source.

 

 

5. Enjoy!

It may take 10-20 seconds before the first records are imported. You can watch the records and dates imported in Settings | Sources. Once records start importing, you can go to the Dashboard tab to see your live network traffic.

Now you can explore all the features of Fastvue Reporter for Palo Alto Networks.

 

 

Upgrading Existing Installations

 

1. Backup Fastvue Reporter’s Data and Settings

If you want to upgrade your existing installation, we recommend backing up your existing settings and data first. This is as simple as making a full copy of the contents of Fastvue Reporter’s data location, shown in Settings | Data Storage | Settings (default is C:\ProgramData\Fastvue\Reporter for Palo Alto Networks).

Tip: Compress the backup, especially the Data.elastic folder as this can be quite large.

 

 

2. Backup Custom IIS Settings (if applicable)

If you have secured the Fastvue Reporter website with IIS or applied any other custom settings in IIS directly, you should also backup the web.config file in the website’s directory (usually under c:\inetpub\wwwroot\<fastvuereporter’s site name>). The installer will attempt to also backup and restore this file for you, but this is a good idea just incase there is an issue with the installation.

 

 

3. Upgrade / Installation

Once your current environment is backed up, download the new installer and run it over the top of your existing installation to upgrade. The installer will pick up your existing settings, so just click next throughout the wizard without making any changes. Once installed, browse to the site and clear the browser cache by hitting ctrl + F5 (cmd + R on Mac).

Note that it can take a few minutes for data to start importing again after upgrades and restarts of the Fastvue Reporter service. You can check the database initialisation progress in Settings | Diagnostic | Database.

 

 

4. Enjoy!

It may take 10-20 seconds before the first records are imported. You can watch the records count in Settings | Sources. Once records start importing, you can go to the Dashboard tab to see your live network traffic.

Now you can test out the many features of Fastvue Reporter for Palo Alto Networks.

 

Quick Navigation;

© Copyright 2000-2023  COGITO SOFTWARE CO.,LTD. All rights reserved