{"id":998,"date":"2013-07-31T06:46:00","date_gmt":"2013-07-31T13:46:00","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=998"},"modified":"2023-02-24T21:48:41","modified_gmt":"2023-02-24T21:48:41","slug":"a-bunch-of-sonicwall-goodiespart-3-analyzer","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/","title":{"rendered":"A bunch of Sonicwall goodies\u2013Part 3, Analyzer"},"content":{"rendered":"<p>If you manage a firewall &#8212; specially a UTM firewall that does all manner of things including tracking \u201ccontent\u201d and \u201capplications \u2013 then chances are you are going to be asked by Management to provide reports and information about the \u201chow\u2019s\u201d and \u201cwho\u2019s\u201d of bandwidth use.&nbsp; It\u2019s a fact of modern corporate life irrespective of the size of the corporation.&nbsp; In fact, you could argue that smaller organizations are even more concerned about bandwidth usage than their larger cousins because the dollars used to pay for the bandwidth are that much dearer.<\/p>\n<p>Any firewall worth its salt can channel syslog output to a syslog server and, of course, you can use any number of tools to sift through that output.&nbsp; Problem is it can be hideously tedious to work out how to sift out the required data and then present it in a format that humans (and Management, for that matter \u2026) can read.&nbsp; Dell Sonicwall has a great tool that fulfills this need.<\/p>\n<p>Sonicwall Analyzer is a licensed product from Dell Sonicwall, available as a Windows application for installation on a Windows server or as a self-contained VMware VM appliance.&nbsp; Analyzer allows you to capture the syslog output from your Sonicwall appliance (includes firewalls as well as SSL VPN appliances) and then slice, dice and and serve it up in a nice graphical format.&nbsp; No, it is not \u201csexy\u201d but yes, it is very useful.<\/p>\n<p>I\u2019ve installed the Analyzer VM at a few sites, including our own office, and the process is relatively painless.&nbsp; Once the VM is installed and started the system asks a few basic configuration questions and the appliance is ready to go.&nbsp; You need to make a change on your Sonicwall device to point syslog output to the Analyzer appliance and then you need to wait a few hours for Analyzer to digest the data that is captured from the Sonicwall.&nbsp; From that point forward&nbsp; you can search through a number of categories and then slice, dice and report on your chosen dataset.<\/p>\n<p>Many organizations use Analyzer to show how bandwidth is used and then adjust rules accordingly.&nbsp; It is a great tool to help ferret out those hidden, high-bandwidth bandits.&nbsp; It also has a bit of a \u201cBig Brother\u201d function in that it allows an admin to profile a user\u2019s Internet use (requires some extra plumbing with Sonicwall SSO in the&nbsp; back end).&nbsp; Some organizations that are&nbsp; loathe to enforce content or application filtering at the firewall can use this function to report use patterns for their users.<\/p>\n<p>As I said, nothing sexy but worth its weight in gold if you are the firewall admin that has been tasked by management to analyze bandwidth use.&nbsp; If you have&nbsp; Dell Sonicwall firewalls (and other Sonicwall devices such as SRA\u2019s) it\u2019s well worth the time investment to look into Analyzer.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you manage a firewall &#8212; specially a UTM firewall that does all manner of things including tracking \u201ccontent\u201d and \u201capplications \u2013 then chances are you are going to be asked by Management to provide reports and information about the \u201chow\u2019s\u201d and \u201cwho\u2019s\u201d of bandwidth use.&nbsp; It\u2019s a fact of modern corporate life irrespective of &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[266],"tags":[293,574,593],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A bunch of Sonicwall goodies\u2013Part 3, Analyzer - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A bunch of Sonicwall goodies\u2013Part 3, Analyzer - Archive\" \/>\n<meta property=\"og:description\" content=\"If you manage a firewall &#8212; specially a UTM firewall that does all manner of things including tracking \u201ccontent\u201d and \u201capplications \u2013 then chances are you are going to be asked by Management to provide reports and information about the \u201chow\u2019s\u201d and \u201cwho\u2019s\u201d of bandwidth use.&nbsp; It\u2019s a fact of modern corporate life irrespective of &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2013-07-31T13:46:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:48:41+00:00\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/\",\"name\":\"A bunch of Sonicwall goodies\u2013Part 3, Analyzer - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"datePublished\":\"2013-07-31T13:46:00+00:00\",\"dateModified\":\"2023-02-24T21:48:41+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A bunch of Sonicwall goodies\u2013Part 3, Analyzer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A bunch of Sonicwall goodies\u2013Part 3, Analyzer - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/","og_locale":"en_US","og_type":"article","og_title":"A bunch of Sonicwall goodies\u2013Part 3, Analyzer - Archive","og_description":"If you manage a firewall &#8212; specially a UTM firewall that does all manner of things including tracking \u201ccontent\u201d and \u201capplications \u2013 then chances are you are going to be asked by Management to provide reports and information about the \u201chow\u2019s\u201d and \u201cwho\u2019s\u201d of bandwidth use.&nbsp; It\u2019s a fact of modern corporate life irrespective of &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/","og_site_name":"Archive","article_published_time":"2013-07-31T13:46:00+00:00","article_modified_time":"2023-02-24T21:48:41+00:00","author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/","url":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/","name":"A bunch of Sonicwall goodies\u2013Part 3, Analyzer - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"datePublished":"2013-07-31T13:46:00+00:00","dateModified":"2023-02-24T21:48:41+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2013\/07\/31\/a-bunch-of-sonicwall-goodiespart-3-analyzer\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"A bunch of Sonicwall goodies\u2013Part 3, Analyzer"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/998"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=998"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/998\/revisions"}],"predecessor-version":[{"id":2997,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/998\/revisions\/2997"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=998"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=998"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=998"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}