57
Trinzic Reporting Sample Report Book

Trinzic Reporting Sample Report2

Embed Size (px)

DESCRIPTION

trinzic

Citation preview

Trinzic Reporting Sample Report Book Trinzic Reporting Sample Report Book 1TRINZIC REPORTING OVERVIEW .........................................................................................................................................4 2DNS REPORTS ...............................................................................................................................................................................5 2.1DNS TOP REQUESTED DOMAINS ......................................................................................................................................................... 5 2.2DNS REPLIES TREND ................................................................................................................................................................................ 6 2.3DNS CACHE HIT RATE TREND .............................................................................................................................................................. 7 2.4DNS QUERY RATE BY QUERY TYPE ................................................................................................................................................... 8 2.5DNS RESPONSE LATENCY TREND ....................................................................................................................................................... 9 2.6DNS TOP CLIENTS .................................................................................................................................................................................. 10 2.7DNS QUERY RATE BY SERVER/SERVER GROUP ....................................................................................................................... 11 2.8DNS DAILY QUERY RATE BY SERVER/SERVER GROUP .......................................................................................................... 12 2.9DNS DAILY PEAK HOUR QUERY RATE BY SERVER/SERVER GROUP ................................................................................. 13 2.10DNS RESOURCE RECORDS LAST QUERIED .................................................................................................................................. 14 2.11DNS ZONES LAST QUERIED ................................................................................................................................................................ 15 2.12DNS STATISTICS PER ZONE ................................................................................................................................................................ 16 2.13DNS STATISTICS PER DNS VIEW ..................................................................................................................................................... 17 2.14DNS TOP CLIENTS PER DOMAIN ....................................................................................................................................................... 18 2.15DNS TOP NXDOMAIN NOERROR (NO DATA) ..................................................................................................................... 19 2.16DNS TOP SERVFAIL ERRORS SENT/RECEIVED ....................................................................................................................... 20 2.17DNS TOP TIMED-OUT RECURSIVE QUERIES ................................................................................................................................ 21 2.18DNS QUERY TREND PER IP BLOCK GROUP ................................................................................................................................ 22 3SECURITY (DNS) REPORTS ..................................................................................................................................................23 3.1DNS TOP RPZ HITS ............................................................................................................................................................................... 23 3.2DNS TOP RPZ HITS BY CLIENT ......................................................................................................................................................... 25 3.3FIREEYE ALERTS REPORT ................................................................................................................................................................... 26 3.4THREAT PROTECTION EVENT COUNT BY TIME ............................................................................................................................. 27 3.5THREAT PROTECTION EVENT COUNT BY SEVERITY TREND .................................................................................................... 28 3.6THREAT PROTECTION EVENT COUNT BY RULE ............................................................................................................................ 29 3.7THREAT PROTECTION EVENT COUNT BY MEMBER/MEMBER GROUP ................................................................................. 30 3.8THREAT PROTECTION EVENT COUNT BY MEMBER/MEMBER GROUP TREND .................................................................. 31 3.9THREAT PROTECTION EVENT COUNT BY CATEGORY ................................................................................................................ 32 4DYNAMIC DNS (DDNS) REPORTS ......................................................................................................................................33 4.1DDNS UPDATE RATE TREND ............................................................................................................................................................. 33 5DHCP REPORTS .........................................................................................................................................................................34 5.1DHCP LEASE HISTORY ......................................................................................................................................................................... 34 5.2DHCP MESSAGE RATE TREND .......................................................................................................................................................... 35 5.3DHCP TOP LEASE CLIENTS ................................................................................................................................................................ 36 5.4DHCPV4 USAGE TREND ....................................................................................................................................................................... 37 5.5DHCPV4 USAGE STATISTICS ............................................................................................................................................................. 38 5.6DHCPV4 RANGE UTILIZATION TREND ............................................................................................................................................. 39 5.7DHCPV4 TOP UTILIZED NETWORKS ................................................................................................................................................ 40 5.8TOP DEVICE CLASSES ............................................................................................................................................................................ 41 5.9DEVICE TREND .......................................................................................................................................................................................... 42 5.10DEVICE TREND .......................................................................................................................................................................................... 43 5.11TOP DEVICES IDENTIFIED ...................................................................................................................................................................... 44 5.12TOP DEVICES DENIED AN IP ADDRESS ........................................................................................................................................... 45 5.13DEVICE FINGERPRINT CHANGE DETECTED ................................................................................................................................... 46 6IP ADDRESS REPORTS ...........................................................................................................................................................47 6.1IPAM V4 NETWORK USAGE STATISTICS ........................................................................................................................................ 47 2014 Infoblox Inc. All rights reserved.Page 2 Trinzic Reporting Sample Report Book 6.2IPAMV4 TOP UTILIZED NETWORKS .................................................................................................................................................. 48 7DEVICE REPORTS ......................................................................................................................................................................49 7.1PORT CAPACITY UTILIZATION BY DEVICE ....................................................................................................................................... 49 7.2INACTIVE IP ADDRESSES....................................................................................................................................................................... 50 7.3PORT CAPACITY TREND ........................................................................................................................................................................ 51 7.4PORT CAPACITY DELTA BY DEVICE .................................................................................................................................................. 52 8APPLIANCE REPORTS.............................................................................................................................................................53 8.1CPU UTILIZATION TREND ..................................................................................................................................................................... 53 8.2MEMORY UTILIZATION TREND ............................................................................................................................................................. 54 8.3TRAFFIC RATE BY SERVER/SERVER GROUP................................................................................................................................. 55 9CUSTOMIZABLE DASHBOARDS .........................................................................................................................................56 2014 Infoblox Inc. All rights reserved.Page 3 Trinzic Reporting Sample Report Book 1TRINZIC REPORTING OVERVIEW Infoblox has provided the industry-leading platform for real-time views and management DNS, DHCP andIPAddressManagement(IPAM)forthepastdecade.TrinzicReportingintegrateswiththe patented Infoblox Grid technology and enhances the real-time management with an extensive and customizable historical reporting engine. Insteadoftryingtocobbletogethermultipleviewsorprintedgraphswhichtakestimeandisoften incorrect, Trinzic Reporting delivers robust reporting capabilities within a single platform and interface.Userscansliceanddicethedatainmanydifferentformatsquicklyandeasilytofindtheexact information they are looking for by dates, locations, users and many other definable parameters. With Infoblox, you have the power and management capability to manage DDI deployments with the mostreliableandsecureservices,thebestreal-timemanagementviewsandrobust,customizable reporting all within a single platform. Thissamplereportbookletincludesmanyofthepre-builtreportsavailablewithTrinzicReporting today.The reports are grouped by: DNS reports Dynamic DNS (DDNS) reports Security (DNS) reports DHCP reports IPAM reports Device reports Infoblox appliance reports Each sample report includes the following information: Description of the report Data presented Filters Formats Sample report graphic For additional information on Trinzic Reporting or other Infoblox products, please contact your local Infoblox representative or call 1-408-625-4200 ext. 2. Please note Trinzic Reporting will have continuous updates to existing reports and add new capabilities over time.This sample report book lists the available reports in the current release of the solution.Customers not on the current release and/or not utilizing all of the products, features, or capabilities may not receive all available reports.This is a sample reporting book and the reports listed here may be reformatted, changed and/or be removed. 2014 Infoblox Inc. All rights reserved.Page 4 Trinzic Reporting Sample Report Book 2DNS REPORTS 2.1DNS Top Requested Domains DescriptionList Top Requested Domain Names OverviewProvides visibility of the top domains being requested (based on filter settings) to help assign proper distribution of resources and identify where users are going or what applications they are accessing. Data presentedDomain Names (Fully Qualified Domain Names) Query Counts per DNS Domain Name Query Percentage (for the time frame) FiltersTime (last hour/day/week/month), Start Time (user defined), End Time (used defined), Members (user defined), TLD (user defined), Top N (user defined or user selected 5-500), FormatsBar Chart, Table Sample report: 2014 Infoblox Inc. All rights reserved.Page 5 Trinzic Reporting Sample Report Book 2.2DNS Replies Trend DescriptionList DNS Query Replies by Reply Code OverviewProvides insight into how effectively DNS queries are being processed. This report can be used to measure successful queries and to identify changes in the number of failed or unsuccessful queries. Data presentedQuery Reply Count by Reply Code SUCCESS / NOERROR REFERRAL NXRRSET NXDOMAIN REFUSED OTHER FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Members (user defined), Response Type (SUCCESS/ NOERROR, REFERRAL, NXRRSET, NXDOMAIN, REFUSED, OTHER) FormatsTable, Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 6 Trinzic Reporting Sample Report Book 2.3DNS Cache Hit Rate Trend DescriptionCache hit ratio by serverOverviewProvides DNS cache hit ratio over time for DNS servers.Helps identify how server is performing, what percent of queries are already in cache and what percent of queries is unique. Data presentedServer Node Cache hit rate (%) By unit of time FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Members (user defined), DNS View (user defined), EA Members Site (user defined) FormatsLine chart, table Sample report: 2014 Infoblox Inc. All rights reserved.Page 7 Trinzic Reporting Sample Report Book 2.4DNS Query Rate by Query Type DescriptionList DNS Query Rates by Query TypeOverviewShows the types of DNS requests by volume over time for DNS servers.Helps pinpoint trends in requests by users across the infrastructure. Data presentedQuery Types (Total, Average, Maximum) AAAA CNAME NS ANY A MX PTR SOA TKEY Other FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Members (user defined), Record Type (A, AAAA, CNAME, DNAME, DNSKEY, DS, NAPTR, NSEC, NSEC3PARM, NSEC3, PTR , RRSIG, SRV, TXT, PRT, NS, MX, SOA, Other) FormatsTable, Stacked Area, Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 8 Trinzic Reporting Sample Report Book 2.5DNS Response Latency Trend DescriptionMap DNS Latency Response time for all or selected cache servers.OverviewProvides the DNS latency or round-trip response time for DNS queries.This data helps identify potential slow or problem areas based on filters. Data presentedOverall DNS response latency in milliseconds FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Members (user defined), EA Member Site (user defined) FormatsStacked line graph, table, line chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 9 Trinzic Reporting Sample Report Book 2.6DNS Top Clients DescriptionShows clients with the most DNS queriesOverviewHighlights the top N requestors shows which clients are sending the most queries over a selected time period.Helps identify top talkers and potential risk areas. Data presentedSource IP addresses Number of queries generated FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Members (user defined), TopN (user defined or user selected 5-500), DNS View (user defined) FormatsTable, Bar graph Sample report: 2014 Infoblox Inc. All rights reserved.Page 10 Trinzic Reporting Sample Report Book 2.7DNS Query Rate By Server/Server Group DescriptionShows trend of DNS QPS by memberOverviewShows the queries per seconds and how much load is being generated and which devices are carrying the load.Helps plan better for capacity and reduce the risk of overloading DNS devices. Data presentedMember names DNS Queries Per Second per member Time FiltersTime (last hour/day/week/month), Start Time (user defined), End Time (used defined), Members (user defined), Members (user defined), TopN (user defined or user selected 5-500), DNS View (user defined), EA Member Site (user defined) FormatsTable, Stacked Area, Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 11 Trinzic Reporting Sample Report Book 2.8DNS Dail y Query Rate by Server/Server Group DescriptionShows daily average or daily maximum query rate trend by member.OverviewShows the daily average or daily maximum query rate by server. It displays a single value per day per server. This report shows how much load is being generated and which devices are carrying the load.Helps plan better for capacity and reduce the risk of overloading DNS devices. Data presentedMember names DNS Queries Per Second per member Time FiltersTime (last week/month/year), Start Time (user defined), End Time (used defined), Top N (user defined or user selected 5-500), Members (user defined), Stats (Avg./Max), DNS View (user defined), EA Member Site (user defined) FormatsTable, Stacked Area, Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 12 Trinzic Reporting Sample Report Book 2.9DNS Dail y Peak Hour Query Rate by Server/Server Group DescriptionShows the maximum or average QPS for the peak hour of the day by memberOverviewTracks the queries per seconds over a peak hour and how much load is being generated and which devices are carrying the load.The peak hour measurement helps plan better for the highest volume load capacity requirements by providing the max hourly query rate instead of averaging over an entire day.This view reduces the risk of overloading DNS devices when they are in the most demand. Data presentedMember names DNS Queries Per day per member Time FiltersTime (last week/month/year), Start Time (user defined), End Time (used defined), Top N (user defined or user selected 5-500), Members (user defined), Stats (Avg./Max), DNS View (user defined), EA Member Site (user defined) FormatsTable, Stacked Area, Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 13 Trinzic Reporting Sample Report Book 2.10DNS Resource Records Last Queried DescriptionDisplays a list of DNS resource records that are not queried since a user defined date. OverviewAllows users to identify DNS resource records that are not queried since a user defined date.User can then use the provided information to delete under-utilized resource records. Data presentedDNS View Network View Zone:Zone Name Record Name: The domain name owner of the record. For hosts, this field displays the canonical name of the host. Record Type: The resource record type. Record Data: Data that the record contains. For host records, this field displays the IP address of the host. Monitored Since: The monitoring start date Last Queried: The date the resource record was last queried FiltersNot Queried Since, DNS View (All, a specific DNS View), Zone (user defined), Type (Resource Record Type) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 14 Trinzic Reporting Sample Report Book 2.11DNS Zones Last Queried DescriptionDisplays a list of DNS zones that are not queried since a user defined date. OverviewAllows users to identify DNS resource records that are not queried since a user defined date.User can then use the provided information to delete under utilized resource records. Data presentedDNS View Network View Zone:Zone Name Monitored Since: The monitoring start date Last Queried: The date the resource record was last queried FiltersNot Queried Since, DNS View (All, a specific DNS View), Zone (user defined), Type (Resource Record Type) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 15 Trinzic Reporting Sample Report Book 2.12DNS Statistics per Zone DescriptionTracks DNS statistics per zone OverviewThis report allows the user to quickly determine the number of resource records assigned to any zone by resource record type.The statistics provided by this report can be used for more effective planning. Data presentedTimestamp Zone Function (Forward-Mapping, IPv4 Reverse-Mapping, IPv6 Reverse-Mapping) Signed Hosts Total Records Count of the following records:A Records, AAAA Records, CNAME Records, DNAME Records, DNSKEY Records, MX Records, NAPTR Records, NSEC Records, NSEC3PARAM Records, NSEC3 Records, NS Records, PTR Records, RRSIG Records, SOA Records, SRV Records, TXT Records and Other Records FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (used defined), Grid Primary (user defined), Microsoft Primary (user defined), DNS View (user defined), Zone Name (user defined), Zone Function (user defined), Signed (yes/no) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 16 Trinzic Reporting Sample Report Book 2.13DNS Statistics per DNS View DescriptionTracks DNS statistics per DNS view OverviewSince every DNS view can have multiple zones and each zone can have multiple records, this report highlights the statistics based on every DNS View Or Member. This report allows you to identify how many Zones and DNS records a member or a DNS view is serving and use these statistics for more effective planning. Data presentedTimestamp View Forward-mapping zones IPV4 Reverse Mapping IPV6 Reverse Mapping Signed Zones Hosts Total records Count of the following records:A Records, AAAA Records, CNAME Records, DNAME Records, DNSKEY Records, MX Records, NAPTR Records, NSEC Records, NSEC3PARAM Records, NSEC3 Records, NS Records, PTR Records, RRSIG Records, SOA Records, SRV Records, TXT Records and Other Records FiltersTime (last minute/hour/day/week/month), Start Time (user defined), End Time (used defined), Members (user defined), DNS View (user defined)

FormatsTable Sample report:

2014 Infoblox Inc. All rights reserved.Page 17 Trinzic Reporting Sample Report Book 2.14DNS Top Clients per Domain DescriptionLists the top N clients and number of queries for all or the specifiedDNS domains OverviewIdentify top users of specific applications, see clients querying a list of malicious domains and track clients to specific domains to improve performance and reduce risk. Data presentedDomain Names (Fully Qualified Domain Names) Query Counts per DNS Domain Name Client FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (used defined), Members (user defined), DNS View (user defined), Domain Name (user defined), TLD (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 18 Trinzic Reporting Sample Report Book 2.15DNS Top NXDOMAIN NOERROR (no data) DescriptionLists DNS queries that result in NXDOMAIN or NOERROR (no data) response OverviewIdentifies queries to servers that have been renamed or removed and finds mis-configurations by showing DNS queries that result in NXDOMAIN and NOERROR(nodata) responses Data presentedDomain name Number of queries FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (used defined), Members (user defined), DNS View (user defined), Reply Type (NXDOMAIN, No Error/No Data) FormatsTable, Bar Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 19 Trinzic Reporting Sample Report Book 2.16DNS Top SERVFAIL Errors Sent/Received DescriptionShows queries that received or sent SERVFAIL responses OverviewAllows users to see if issues reside within their DNS servers or upstream name servers by showing queries that receive/send SERVFAIL responses from upstream name serves. Data presentedDomain name Number of queries (sent or received) FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (used defined), Members (user defined), DNS View (user defined) FormatsBar chart, table Sample report: 2014 Infoblox Inc. All rights reserved.Page 20 Trinzic Reporting Sample Report Book 2.17DNS Top Timed-Out Recursive Queries DescriptionLists DNS queries that time out OverviewReduces troubleshooting time by showing the top DNS queries that resulted in Infoblox name servers timing out when sending queries to upstream name servers. Data presentedDomain name Number of queries FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (used defined), Members (user defined), DNS View (user defined) FormatsTable,Bar Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 21 Trinzic Reporting Sample Report Book 2.18DNS Query Trend Per IP Block Group DescriptionDNS Query Trend Per IP Block Group OverviewReduces time to identify issues by identifying the top DNS queries by selected IP Block Group.This allows for detailed filtering on a selected group or multiple groups.In addition, the enterprise or service provider can plan better for future growth requirements by tracking usage or top talkers across different regions. Data presentedTime Group Query count FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Aggregation Time (5 minutes, 30 minutes, 1 hour, 12 hours, 1 day), Members (user defined), DNS View (user defined), Groups (user defined) FormatsTable,Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 22 Trinzic Reporting Sample Report Book 3SECURITY (DNS) REPORTS 3.1DNS Top RPZ Hits DescriptionLists the top hits to domains defined in the Response Policy ZoneOverviewIdentifies domains in the RPZ which have the most hits that have been on qualified as malicious domains. Report is designed to shorten the time to identify malware impacts by tracking when attempts are made to reach domains on the RPZ list including number of hits and time.This report is available for customers with Infoblox DNS Firewall. Data presentedClient ID Selecting Client ID will display the lease history for the client when information is available in the lease historyTotal Client Hits Domain Name Total Rule Hits Mitigation Action Substitute Addresses Time FiltersTime (last hour/day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (used defined), Client (user defined), Members (user defined), DNS View (user defined), Domain Name (user defined), Mitigation Action (Passthru, Block, Substitute, Error), RPZ Zone (user defined), RPZ Entry (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 23 Trinzic Reporting Sample Report Book 2014 Infoblox Inc. All rights reserved.Page 24 Trinzic Reporting Sample Report Book 3.2DNS Top RPZ Hits by Client DescriptionLists the top client IDs and hits to domains defined in the Response Policy ZoneOverviewTracks when client IDs attempt to reach domains on the RPZ list including number of hits and time which shortens time to identify clients impacted by malware by identifying who may be infected.This report is available for customers with Infoblox DNS Firewall. Data presentedClient ID Selecting Client ID will display the lease history for the client when information is available in the lease historyTotal Client Hits Total Rule Hits Substitute Addresses Time FiltersTime (last hour/day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (used defined), Client (user defined), Members (user defined), DNS View (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 25 Trinzic Reporting Sample Report Book 3.3FireEye Alerts Report DescriptionTracks logs and alerts from FireEye appliance OverviewProvides date/time, alert ID and log severity for FireEye block alerts provided via Infoblox DNS Firewall FireEye Adapter.Validates operation of DNS Firewall, Infoblox FireEye Adapter and FireEye NX appliances.This report is available for customers with Infoblox Fireeye Adapter. Data presentedTime Alert ID Log Severity Alert Type FireEye Appliance FiltersTime (last minute/hour/day/week/month/year), Alert ID (user defined), Log Severity (critical/invalid, major/minor), Alert Type (infection events, web infection, malware object, domain match, callback events), FireEye appliance (user defined), Start Time (user defined), End Time (user defined), Mitigation Action Passthru, Block, Substitute, Error), RPZ Entry (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 26 Trinzic Reporting Sample Report Book 3.4Threat Protection Event Count by Time DescriptionList of attacks that happened across the network ordered by timestamp OverviewHelps identify if an attack is short lived or is a prolonged threat, if attacks are happening at different points in the network at the same time etc.This report is available for customers with Infoblox Advanced DNS Protection. Data presentedTime SID Member Category Log Severity Event Name Alert Count Drop Count Total Event Count FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Category (user defined), Log Severity (critical, major, warning, informational), Rule ID (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 27 Trinzic Reporting Sample Report Book 3.5Threat Protection Event Count by Severity Trend DescriptionShows attacks categorized by severity OverviewProvides graphical representation of all attacks categorized by severity levels (pre-defined) critical, informational and major. Helps understand severity trends at different times, on different members, by category etc. to take corrective measures.This report is available for customers with Infoblox Advanced DNS Protection. Data presentedEvent count Severity Type Time FiltersTime (last minute/hour/day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (user defined), Members (user defined), Category (user defined), Log Severity (critical, major, warning, informational), Rule ID (user defined) FormatsStacked Area Sample report: 2014 Infoblox Inc. All rights reserved.Page 28 Trinzic Reporting Sample Report Book 3.6Threat Protection Event Count by Rule DescriptionShows attacks by pre-defined threat rules OverviewHelps identify most used threat rules for protection, providing intelligence on common threats to DNS. This report is available for customers with Infoblox Advanced DNS Protection. Data presentedSID Category Log Severity Event Name Alert Count Drop Count Total Event Count FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Category (user defined), Log Severity (critical, major, warning, informational), Rule ID (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 29 Trinzic Reporting Sample Report Book 3.7Threat Protection Event Count by Member/Member Group DescriptionShows attacks happening on each member in the network OverviewHelps identify severity of attacks happening on a member, and to pinpoint which member(s) are frequent targets for different kinds of attacks. This report is available for customers with Infoblox Advanced DNS Protection. Data presentedMember Critical Event Count Major Event Count Warning Event Count Informational Event Count Total Event Count FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Category (user defined), Rule ID (user defined), EA Member Site (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 30 Trinzic Reporting Sample Report Book 3.8Threat Protection Event Count by Member/Member Group Trend DescriptionShows members targeted the most with DNS attacks OverviewProvides a graphical representation of Top N members that have been attacked over a selected time period. Helps identify points of risk in the network and take appropriate action.This report is available for customers with Infoblox Advanced DNS Protection. Data presentedTime Member Event Count FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Category (user defined), Log Severity (critical, major, warning, informational), Rule ID (user defined), Top N (user defined or user selected 5-500), EA Member Site (user defined) FormatsLine Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 31 Trinzic Reporting Sample Report Book 3.9Threat Protection Event Count by Category DescriptionShows attacks by threat categoryOverviewHelps identify which category of attacks is more frequent over a given time period or targeted to specific members. This report is available for customers with Infoblox Advanced DNS Protection. Data presentedCategory Critical Event Count Major Event Count Warning Event Count Informational Event Count Total Event Count FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Category (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 32 Trinzic Reporting Sample Report Book 4DYNAMIC DNS (DDNS) REPORTS 4.1DDNS Update Rate Trend DescriptionShows DDNS update count by response yype OverviewShows the specific DDNS updates (by type) received by a selected IP address over a given time period.Allows better tracking and trending for planning. Data presentedTimestamp Success Failure Reject Prerequisite Reject FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), Members (user defined), Response Type (Success, Failure, Reject, Prerequisite Reject), Source IP Address (user defined), DNS Zone (user defined), DNS View (user defined) FormatsTable, Line chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 33 Trinzic Reporting Sample Report Book 5DHCP REPORTS 5.1DHCP Lease History DescriptionShows DHCP history for the given timeframe.OverviewProvides time-sequenced list of which MAC address requested an IP address and when.Assists with troubleshooting or compliance tracking and auditing. Data presentedTime: The date and time when the lease was issued. Member/Server: The DHCP member that granted the lease. Member IP Address: The IP address of the DHCP member that granted the lease. Protocol: Indicates if the lease is for an IPv4 or IPv6 address. Action: This can be one of the following: Issued, Renewed, Freed, or Abandoned Lease IP:The IP address of the lease MAC Address: The MAC address of the lease. Host Name: The host name that the DHCP client sent to the appliance using DHCP option 12. Start: The start date of the lease. Stop: The end date of the lease. Fingerprint:The operating system that acquired the lease. FiltersTime range (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Lease IP (user defined), Member IP (user defined), Protocol (IPv4, IPv6), Action (Abandoned, BOOTP, Declined, Expired, Fixed, Free, Issued, Offered, Renewed, Reserved, Unrecognized), Hostname (user defined), MAC DUID (user defined), Lease Start (user defined), Lease End (user defined), Fingerprint (user selected), Device Class (user selected) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 34 Trinzic Reporting Sample Report Book 5.2DHCP Message Rate Trend DescriptionDHCP messages rate trend by IP protocol (4 or 6). OverviewTrends DHCP message rate over time broken down by message time.Helps find unplanned or dangerous activities such as abnormal levels caused by a request storm. Data presentedDiscovers Requests Releases Offers Acks/Nacks Declines Informs IPv6 Message Types IPv6 OthersIPv4 Others FiltersTime (last day/week/month/year), Start Time (user defined), End Time (used defined), DHCP Message Type (user defined), Members (user defined), Protocol (IPv4, IPv6), Statistics (None, Min, Avg, Max) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 35 Trinzic Reporting Sample Report Book 5.3DHCP Top Lease Clients DescriptionTop DHCP activity by MAC/DUID address OverviewShows the top N generators of DHCP by message type.Helps identify heavy internal users or pinpoint security risks of unplanned activity. Data presentedShows Top Requester in terms of #of DHCP lease requests #of DHCP lease renews#of DHCP lease releases FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Top N (user defined or user selected 5-500), Protocol (All, IPv4, IPv6), Report on (issues, renewed, freed), Fingerprint (user selected), Device Type (user selected) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 36 Trinzic Reporting Sample Report Book 5.4DHCPv4 Usage Trend DescriptionDHCPv4 usage overall for a given time window and IPv4 network address range provide usage snapshot OverviewShows DHCP utilization trends across an entire IP address space or selection range and trends over time.Helps identify utilization changes and improves planning to handle ongoing variations. Data presentedTotal IP address space associated to DHCP range Dynamic: Number of DHCP leases issued for the selected Static: Number of static DHCP addresses configured Free: Number of available (unused) DHCP addresses FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Address (user defined), Microsoft Servers (user defined), DHCP Range (user defined) FormatsTable, Stacked Area, Line Chart Sample report:

2014 Infoblox Inc. All rights reserved.Page 37 Trinzic Reporting Sample Report Book 5.5DHCPv4 Usage Statistics DescriptionDHCP usage overall for a given time window and IPv4 network address range provide usage snapshot OverviewShows the DHCP usage and activity over time for a selected IP address range.Provides detailed visibility into usage at any point in time which assists with troubleshooting or compliance auditing requirements. Data presentedNetwork View Subnet Subnet Mask(CIDR) #of DHCP Ranges Provisioned: Total IP address space associated to DHCP zones Utilization rate: DHCP utilization Status: DHCP utilization status by threshold [full, high, low, normal]. Dynamic: Number of DHCP leases issued for the selected Static: Number of static DHCP addresses configured Free: Available/un used IP addressesTotal In use: Total number of Dynamic and Static addresses FiltersTime (last minute/hour/day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Network View (user defined), Network (user defined), Address (user defined), Microsoft Servers (user defined), CIDR (user defined), Utilization Rate (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 38 Trinzic Reporting Sample Report Book 5.6DHCPv4 Range Utilization Trend DescriptionDHCP utilization by IPv4 network range and time frameOverviewHighlights the DHCP range utilization for selected address ranges over time.Allows for better tracking and trending of DHCP resources to avoid overutilization. Data presentedDHCP utilization per member FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Microsoft Servers (user defined), DHCP Range (user defined), Network (user defined), TopN (user defined or user selected 5-500) FormatsTable, Line Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 39 Trinzic Reporting Sample Report Book 5.7DHCPv4 Top Utilized Networks DescriptionTracks the utilization of DHCP by subnet OverviewShows the most utilized subnets in terms of IP address consumption including the DHCP range in each subnet.Helps track usage trends over time and plan for future resource allocation. Data presentedTimestamp Network View Network CIDR DHCPv4 Utilization % Ranges Provisioned Dynamic Static Free Used FiltersTime Range (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Microsoft Servers (user defined), Top N (user defined or user selected 5-500) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 40 Trinzic Reporting Sample Report Book 5.8Top Device Classes DescriptionTop Device Classes OverviewIdentifies and highlights the top device operating systems broken down by classes that receive DHCP leases.Helps identify which manufacturers and operating systems are being used so IT can identify non-supported devices or plan for future requirements. Data presentedDeviceTotal % of all devices FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), DHCP Range (user defined), CIDR (user defined), Fingerprint (user selected), Device Class (user selected) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 41 Trinzic Reporting Sample Report Book 5.9Device Trend DescriptionTracks the device class trend over time OverviewIdentifies and highlights the top device operating systems broken down by class that receive DHCP leases over time.Helps identify which device classes are being used so IT can find trends, identify non-supported devices or plan for future requirements. Data presentedTimestamp Device Count Device Class FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), DHCP Range (user defined), CIDR (user defined), Fingerprint (user selected), Device Class (user selected) FormatsLine chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 42 Trinzic Reporting Sample Report Book 5.10Device Trend DescriptionTracks the device type trend over time OverviewIdentifies and highlights the top device operating systems that receive DHCP leases over time.Helps identify which manufacturers and operating systems are being used so IT can find trends in usage, identify non-supported devices or plan for future requirements. Data presentedTimestamp Device CountDevice Class FiltersTime (last day/week/month/year), Top N (10-500), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), DHCP Range (user defined), CIDR (user defined), Fingerprint (user selected), Device Class (user selected) FormatsLine Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 43 Trinzic Reporting Sample Report Book 5.11Top Devices Identified DescriptionTracks the devices identified OverviewIdentifies and highlights the top device operating systems that receive DHCP leases.Helps identify which manufacturers and operating systems are being used so IT can find trends in usage, identify non-supported devices or plan for future requirements. Data presentedFingerprintTotal % of all devices Lease IP MAC/DUID FiltersTime (last day/week/month/year), Top N (4-500), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), DHCP Range (user defined), CIDR (user defined), Fingerprint (user selected), Device Class (user selected) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 44 Trinzic Reporting Sample Report Book 5.12Top Devices Denied an IP Address DescriptionTracks devices that were denied an IP address OverviewIdentifies the top number of devices that were denied an IP address using DHCPv4 Fingerprint Filters.Helps pinpoint potential problem areas regarding the attempted use of devices that do not comply to corporate use policy. Data presentedMAC/DUID Device Type Device Class Network Attempts Last Attempt FiltersTime (last day/week/month/year), Top N (user defined or user selected 5-500), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), DHCP Range (user defined), CIDR (user defined), Fingerprint (user selected), Device Class (user selected) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 45 Trinzic Reporting Sample Report Book 5.13Device Fingerprint Change Detected DescriptionTracks when a device changes fingerprint type OverviewIdentifies and highlights when the device identified using DHCP Fingerprinting has changed. Helps identify attempts to misrepresent a device through a method called MAC Spoofing.It can also be used to identify when a desktop is using Virtual Machine software or software such as Apples Bootcamp.Data presentedTimestamp MAC/DUID Current Device Type Current Device Class Previous Device Type Previous Device Class Lease IP Action FiltersTime (last hour/day/week), Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), DHCP Range (user defined), CIDR (user defined), Current Fingerprint (user selected), Previous Fingerprint (user defined), Current Device Class (user selected), Previous Device Class (user selected), Device Class Changed (yes/no) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 46 Trinzic Reporting Sample Report Book 6IP ADDRESS REPORTS 6.1IPAM v4 Network Usage Statistics DescriptionTracks usage statistics for IPv4 networksOverviewProvides detailed views of usage based on individual networks/subnets.Helps administrators plan for network/subnet capacity and track usage over time. Data presentedTimestamp Network view Network CIDR DHCPv4 utilization % Total Allocated Reserved Assigned Protocol Utilization % Unmanaged FiltersTime (last minute/hour/day/week/month/year) Start Time (user defined), End Time (user defined), Members (user defined), Network (user defined), Network View (user defined), Utilization Rate (user defined), CIDR (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 47 Trinzic Reporting Sample Report Book 6.2IPAMv4 Top Utilized Networks DescriptionProvides statistics on top utilized networks OverviewProvides view into the top utilized subnets measured by utilization metrics.Helps slice and dice the data into usable formats for improved planning. Data presentedTimestamp Network view Network CIDR size Utilization % Total Assigned Reserved Unmanaged FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), Top N (user defined or user selected 5-500) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 48 Trinzic Reporting Sample Report Book 7DEVICE REPORTS 7.1Port Capacity Utilization by Device DescriptionTracks Port Capacity Utilization by Device OverviewTracks the port capacity by monitoring end-hosts connected to switch ports.The detailed views of operation and admin up/down status with total port counts help with faster troubleshooting and improved capacity planning with up-to-date visibility.This report is available for customers with Infoblox Network Insight. Data presentedDevice NameAdmin Up/Operation Down Admin Down/Operation Down Admin Up/Operation Down Total Available Network View FiltersStart time (user defined), Network view (user define), Device name (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 49 Trinzic Reporting Sample Report Book 7.2Inactive IP Addresses DescriptionIdentifies IP Addresses that are inactiveOverviewMonitors and tracks the last time IP addresses were used and reports on all IP addresses that are inactive.This view allows users to clean up unused IP addresses which reclaims IP addresses for future requirements, shrinks the data requirements and improves visibility.This report is available for customers with Infoblox Network Insight. Data presentedIP Address Last MAC/DUID Type Device Name Device Type Port/Interface Network View FiltersStart time (user defined), Network view (user define), Device name (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 50 Trinzic Reporting Sample Report Book 7.3Port Capacity Trend DescriptionMonitors Port Capacity Utilization over time with historical visibility OverviewTracks the port capacity by monitoring end-hosts connected to switch ports over time.The trending views of operation and admin up/down status highlights utilization over time to plan better with enhanced visualization.This report is available for customers with Infoblox Network Insight. Data presentedPort Count Time Admin Up/Operation Up Admin Down/Operation Down Admin Up/Operation Down Total Available FiltersStart time (user defined), End time (user defined), Network view (user define), Device name (user defined) FormatsLine Chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 51 Trinzic Reporting Sample Report Book 7.4Port Capacity Delta by Device DescriptionTracks the change in Port Capacity by Device over time OverviewMonitors the port capacity over time and identifies the delta over time between admin and operation up/down status.The data helps identify which devices have had the biggest or smallest changes in status over a defined period which helps with capacity planning.This report is available for customers with Infoblox Network Insight. Data presentedDevice NameAdmin Up/Operation Down Start and End Admin Down/Operation Down Start and End Admin Up/Operation Down and End Total Available Network View FiltersStart time (user defined), End time (user defined), Network view (user define), Device name (user defined) FormatsTable Sample report: 2014 Infoblox Inc. All rights reserved.Page 52 Trinzic Reporting Sample Report Book 8APPLIANCE REPORTS 8.1CPU Utilization Trend DescriptionCPU Utilization trend for a given appliance.OverviewProvides CPU utilization by appliance over time.Helps pinpoint potential risk areas where additional resources may be required and assists with planning for future requirements by seeing trends over time. Data presentedCPU Utilization per Infoblox Member FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), TopN (user defined or user selected 5-500) FormatsTable, line chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 53 Trinzic Reporting Sample Report Book 8.2Memory Utilization Trend DescriptionMemory Utilization trend for a given appliance.OverviewProvides memory utilization by device over time.Helps pinpoint potential risk areas where additional resources may be required and assists with planning for future requirements by seeing trends over time. Data presentedMemory Utilization per Infoblox Member FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), TopN (user defined or user selected 5-500), EA Member Site (user defined) FormatsTable, line chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 54 Trinzic Reporting Sample Report Book 8.3Traffic Rate by Server/Server Group DescriptionTraffic rate associated with appliance service interface.OverviewShows traffic rate in and out of LAN port over time with selected appliances.Helps plan for current and future requirements with more detailed data. Data presentedInbound traffic to all Interface (Bits / sec) Outbound traffic to all Interface (Bits / sec) FiltersTime (last day/week/month/year), Start Time (user defined), End Time (user defined), Members (user defined), TopN (user defined or user selected 5-500), EA Member Site (user defined) FormatsTable, line chart Sample report: 2014 Infoblox Inc. All rights reserved.Page 55 Trinzic Reporting Sample Report Book 9CUSTOMIZABLE DASHBOARDS DescriptionCustomizable DashboardsOverviewTrinzic Reporting allows individual users to create individual or multiple dashboards to highlight pertinent information for their respective tasks. Users can select anywhere from two to eight individual reports and create a single-view custom report highlighting the selected information.This view provides a high-level dashboard view to see trends and spikes and allows users to drill down into individual reports for more detailed information. Data presentedThe data presented will be reflective of the selected reports.Users can customize the views based on individual reports. FiltersThe filters will be reflective of the selected reports.Users can customize the views based on individual reports. FormatsMultiple based on selected reports Sample report: 2014 Infoblox Inc. All rights reserved.Page 56 Trinzic Reporting Sample Report Book 2013 Infoblox Inc. All rights reserved.Page 57