Top Clients Report
Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes
The Top Clients report displays summary of the clients that use the most bandwidth on your network, or establish the most connections.
This report is available when log messages with data for this report exist in the specified time frame. To make sure that your Firebox sends log messages required to generate this report, follow the steps to Enable Logging for this Report.
How to Use this Report
This report can help you to identify the top users or hosts on your network by bandwidth or connections (hits). Here are some ways to use this report:
- If your network is close to capacity, select the Users or Hosts pivots and filter by Bandwidth to identify the top consumers of bandwidth.
- Select the Users pivot to identify users who establish more connections or consume significantly more bandwidth than expected for their role in your organization.
- To identify the top connections in a flood attack, select the Hosts (Received) pivot.
View the Report
This report is available in WatchGuard Cloud and in Dimension.
- Log in to WatchGuard Cloud.
- Select Monitor > Devices.
- Select a folder or a specific device.
- To select the report date range, click .
- From the list of reports, select Traffic > Top Clients.
The Top Clients report opens.
- To see reports for your Fireboxes or FireClusters, select Home > Devices.
The Devices list opens.
To see reports for your groups of Fireboxes, select Home > Groups.
The Groups list opens. - Select the Name of a Firebox, cluster, or group.
The Tools > Executive Dashboard page opens. - Select the Reports tab.
- Select Traffic > Top Clients.
The Top Clients report opens.
Pivots
You can use pivots to change the view of the data on the report.
To switch to a different view, select a pivot from the drop-down list above the report.
This report includes these pivots:
Hosts (Sent & Received)
Summary of the bandwidth data or hits for the clients based on the host names used to send and receive the traffic.
Users (Sent & Received)
Summary of the bandwidth data or hits for the clients based on the user names used to send and receive the traffic.
Hosts (Sent)
Summary of the bandwidth data or hits for the clients based on the host names used to send the traffic.
Users (Sent)
Summary of the bandwidth data or hits for the clients based on the user names used to send the traffic.
Hosts (Received)
Summary of the bandwidth data or hits for the clients based on the host names that received the traffic.
Users (Received)
Summary of the bandwidth data or hits for the clients based on the user names that received the traffic.
Detail View
Detail view is not available for this report.
Enable Logging for this Report
Logging for cloud-managed Fireboxes is automatically enabled. For locally-managed Fireboxes, you must manually enable logging in Fireware Web UI or Policy Manager.
To collect the data required for this report for locally-managed Fireboxes, in Fireware Web UI or Policy Manager:
- In the Logging and Notification settings for all packet filters, select Send a log message for reports. For more information, see Set Logging and Notification Preferences.
- In the General Settings for all proxy actions, select Enable logging for reports.