Cisco Cisco Content Security Management Appliance M160 Guía Del Usuario
4-26
AsyncOS 8.3 for Cisco Content Security Management User Guide
Chapter 4 Using Centralized Email Security Reporting
Understanding the Email Reporting Pages
Note
To see which hosts sent virus-infected messages to your network, go to the Incoming Mail page, specify
the same reporting period, and sort by virus positive. Similarly, to see which IP addresses have sent virus
positive email within your network, view the Outgoing Senders page and sort by virus positive messages.
the same reporting period, and sort by virus positive. Similarly, to see which IP addresses have sent virus
positive email within your network, view the Outgoing Senders page and sort by virus positive messages.
From the Virus Types page you can also generate a PDF or export raw data to a CSV file. For
information on printing or exporting a file, see the
information on printing or exporting a file, see the
.
Note
You can generate a scheduled report for the Virus Types page. See the
URL Filtering Page
•
URL Filtering report modules are populated only if URL filtering is enabled.
•
URL Filtering reports are available for incoming and outcoming messages.
•
Only messages that are scanned by the URL filtering engine (either as part of anti-spam/outbreak
filter scanning or through message/content filters) are included in these modules. However, not all
of the results are necessarily specifically attributable to the URL Filtering feature.
filter scanning or through message/content filters) are included in these modules. However, not all
of the results are necessarily specifically attributable to the URL Filtering feature.
•
The Top URL Categories module includes all categories found in messages that have been scanned,
whether or not they match a content or message filter.
whether or not they match a content or message filter.
•
Each message can be associated with only one reputation level. For messages with multiple URLs,
the statistics reflect the lowest reputation of any URL in the message.
the statistics reflect the lowest reputation of any URL in the message.
•
URLs in the global whitelist configured at Security Services > URL Filtering are not included in
reports.
reports.
URLs in whitelists used in individual filters are included in reports.
•
Malicious URLs are URLs that Outbreak Filters have determined to have poor reputation.
Suspicious URLs are those that Outbreak Filters have determined to require click-time protection.
Suspicious URLs have therefore been rewritten to redirect them to the Cisco Web Security proxy.
Suspicious URLs are those that Outbreak Filters have determined to require click-time protection.
Suspicious URLs have therefore been rewritten to redirect them to the Cisco Web Security proxy.
•
Results of URL category-based filters are reflected in content and message filter reports.
Table 4-10
Details on the Email > Reporting > Virus Types Page
Section
Description
Time Range (drop-down list)
A drop-down list that can range from a day to 90 days or a
custom range. For more information on time ranges and
customizing this for your needs, see the
custom range. For more information on time ranges and
customizing this for your needs, see the
.
Top Incoming Virus Types Detected
This section displays a chart view of the viruses that have been
sent to your network.
sent to your network.
Top Outgoing Virus Types Detected
This section displays a chart view of the viruses that have been
sent from your network.
sent from your network.
Virus Types Detail
An interactive table that shows the details of each virus type.