Distributed Event Detection and Replay

The Solera appliance can search its data-repository, while also allowing the administrator to define “interesting-content” events on the SonicWall. The level of logging detail and frequency of the logging can be configured by the administrator. Nearly all events include Source IP, Source Port, Destination IP, Destination Port, and Time. SonicOS Enhanced has an extensive set of log events, including:

Debug/Informational Events—Connection setup/tear down
User-events—Administrative access, single sign-on activity, user logins, content filtering details
Firewall Rule/Policy Events—Access to and from particular IP:Port combinations, also identifiable by time
Interesting-content at the Network or Application Layer—Port-scans, SYN floods, DPI or AF signature/policy hits

The following is an example of the process of distributed event detection and replay:

1

2
3
4
5
6