(Optional) Add queries
to the Query Builder to filter the report output by attributes such
as source/destination IP addresses, users, or zones. For example,
if you know that traffic initiated from the IP address 192.0.2.0
contains no potential botnet activity, you can add not (addr.src in 192.0.2.0) as
a query to exclude that host from the report output. Connector—Select
a logical connector (and or or).
If you select Negate, the report will exclude
the hosts that the query specifies. Attribute—Select a zone, address,
or user that is associated with the hosts that the firewall evaluates
for botnet activity. Operator—Select an operator to relate
the Attribute to a Value. Value—Enter a value for the query
to match.
|