FQDN Filtering

This view provides detailed visibility, filtering and analytical options for events recorded from the FQDN Filtering configuration. FQDN Filtering events contribute to one of three event types: Firewall Events, Network Events and Web Attacks.

Event Details

Description

Date and Time

ISO 8601 format: YYYY-MM-DD T HH:MM:SS:S Example: 2020-11-22T10:58:46.820.

Type

FQDNFILTER.

CSP Account

Multicloud Defense CSP Account.

Gateway

Multicloud Defense Gateway.

Region

Region of the Multicloud Defense Gateway.

Level

DEBUG, INFO, NOTICE, WARNING, ERROR, CRITICAL, ALERT, EMERGENCY.

Session ID

..

Service

Description

Src IP

Source IP Address.

Src Port

Source Port.

Dest IP

Destination IP Address.

Dest Port

Destination Port.

Protocol

UDP, TCP.

Action

Description

Action

ALLOW, DENY.

State

ESTABLISHED, CLOSE, CLOSED, CLOSE_WAIT, TIME_WAIT, FIN_WAIT, LAST_ACK.

HTTP Request

Description

Host

Host portion of URL.

Method

GET, PUT, POST, HEAD, DELETE, PATCH, OPTIONS.

URI

URI Identifier RFC 3986.

FQDN

Description

FQDN

Fully Qualified Domain Name.

Category Name

Category classification of the FQDN. Example: Social Media.

Reputation

Reputation score of the FQDN.

Rule

Description

ID

ID number/description of Multicloud Defense Rule. Example 59 (egress-prod-apt-80).