Sensor Statistics can be viewed in the Traffic Statistics page. On the Traffic Statistics page, you can choose from the following tabs that display different type of Sensor statistics.
Steps:
For a standalone Sensor, click Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Traffic Statistics.
For Sensors in a stack, click Devices → <Admin Domain Name> → Devices → <Device Name> → Member Sensors → <Stackname-node id> → Troubleshooting → Traffic Statistics.
Click on a tab from the available tabs to obtain the required Sensor statistics.
Click Save as CSV to save and view the selected report in CSV format.
Follow a similar procedure and select other tabs for Sensor Performance to view the relevant Sensor Statistics.
List of tabs for Sensor Statistics
Traffic Received/Sent: You can view the statistics of the total number of packets received (Rx) and transmitted (Tx) for a given device per port. You can select the port from the Port drop-down list for which you want to view the sent/received data. The All Ports option is selected by default and displays information for all the ports. When you hover the mouse over a port in the Port drop-down list, a tooltip displays the status of the port as Link Up, Link Down, or Disabled.
Flows: You can view the statistical TCP and UDP flow data processed by a device. Checking your flow rates can help you determine if your device is processing traffic normally. This also provides you with a view of statistics, such as the available flows supported, as well as the number of active TCP and UDP flows.
Dropped Packets: Using this tab, you can view the reason and the packet drop rate on a port for a device. The All Ports option is selected by default and displays information for all the ports.
Advanced Malware Analysis: You can view the statistics of the malware detected for a given device. The By Malware Engine option displays the malware detected data based on the malware engines configured for the device. The By File type option displays data based on the file type analyzed.
Advanced Callback Detection: You can view the count for number of alerts generated for various bot activities and other suspicious callback activity. This provides information on the amount of suspicious callback activity, and also communication attempts to the C&C servers.
SSL Decryption statistics: Using this tab, you can view the following statistics for SSL decryption:
Sensor Statistics: This tab displays the count for the following for SSL traffic:
Recycled SSL Flows - Total number of SSL flows that have not been recently used and have been freed by the Sensor.
SSL Flow Allocation Errors - Total number of SSL flows the Sensor could not allocate due to resource unavailability.
Skipped SSL Flows Due to Flow Allocation Errors - The Sensor could not allocate new SSL flows due to resource unavailability. This indicates total SSL flows that were skipped as the Sensor could not process them.
Packets Received from Unknown SSL Flows - Total number of SSL packets received that did not have a corresponding SSL flow.
SSL Flows Using Unsupported Diffie-Hellman Cipher Suite - Diffie Hellman cipher suite to encrypt the SSL flow. The Sensor will not be able to detect attacks in this SSL connection.
SSL Flows Using Unsupported Export Cipher - Total flows that used SSLv3/TLS export cipher were negotiated, which the Sensor cannot decrypt due to the use of unsupported RSA cipher suite.
SSL Flows Using Unsupported or Unknown Cipher - Total flows where unsupported or unknown cipher was used.
Internal Web Server Certificate Matches: This tab displays the count for unmatched and matched certificates for inbound SSL traffic.