Firewall Success Metrics
Firewall Success Metrics
About the Data
Data Refresh Frequency: Updated daily at around 09:00 AM (UTC-05:00).
Displays Data for: Firewall activity, including component evaluations, quarantines, auto-releases, malicious components, component risk classifications, waivers, and quarantine response performance.
Minimum Requirements: Requires Sonatype Repository Firewall version 206 or later.
Overview
The Firewall Success Metrics dashboard provides visibility into component evaluation, quarantine activity, malicious component activity, waiver activity, and quarantine response performance across Sonatype Repository Firewall.
This dashboard helps security, platform, and engineering teams understand how Firewall is performing across protected ecosystems and policies. Use this dashboard to review quarantine and auto-release trends, malicious component activity, component risk classification, waiver usage, and the time it takes for quarantined components to be resolved.
Use filters such as date range, ecosystem, quarantine type, and quarantine reason to refine your view and analyze Firewall activity across the selected time period.
About Firewall Success Metrics
Firewall Success Metrics surfaces information about components evaluated and processed by Sonatype Repository Firewall.
This dashboard helps you understand:
- Components Evaluated: Total number of components evaluated within the selected time period.
- Components Quarantined: Total number of components quarantined within the selected time period.
- Components Auto-released: Total number of components automatically released from quarantine within the selected time period.
- Malicious Components: Total number of malicious components detected within the selected time period.
- Components Waived: Total number of components waived within the selected time period.
- Avg Quarantine Time: Average amount of time components remain in quarantine before being released.
- Sonatype Firewall Activity Over Time: Daily counts of evaluated, quarantined, and malicious components over the selected period.
- Quarantine Reasons: Distribution of quarantined components by quarantine reason.
- Malicious Threat categories: Distribution of quarantined threats by category.
- Component Risk Classification: Component-level quarantine details by component name, quarantine reason, threat type, and integrity quarantine score.
- Quarantine Response Performance: Time taken to resolve quarantined components, grouped by time-to-resolve range.
- Waiver Activity Over Time: Daily counts of auto waivers, manual waivers, and total waivers over the selected period.
- Waivers: Details about waived components by threat level, policy name, component name, created date, and waiver expiry date.
By surfacing this data, the dashboard provides visibility into Firewall activity and helps teams evaluate quarantine behavior, malicious component detection, waiver activity, and quarantine response performance.
Downloading Dashboard and Table Data
You can download dashboard and table data using the dashboard export options. For instructions on exporting dashboards, tables, and scheduling deliveries, see Exporting Dashboards and Table Data.
Explore Your Firewall Success Metrics Dashboard
Our dynamic dashboard lets you drill into Firewall success metrics with a focused set of filters. Narrow your view by date range, ecosystem, quarantine type, and quarantine reason.
Date Range: Defaults to a relative time selection. Adjustable to custom or predefined time periods.
Ecosystem: Filter by package ecosystem.
Quarantine Type: Filter by quarantine type.
Quarantine Reason: Filter by quarantine reason.
Use these filters to narrow the dashboard view and focus on Firewall activity across the selected time period.
Components Evaluated
This metric displays the total number of components evaluated within the selected time period. Use this metric to understand the volume of component activity evaluation by Firewall.
Components Quarantined
This metric displays the total number of components quarantined within the selected time period. Use this metric to understand the volume of components blocked by quarantine actions.
Components Auto-Released
This metric displays the total number of components automatically released from quarantine within the selected time period. Use this metric to understand how many quarantined components were released without manual action.
Malicious Components
This metric displays the total number of malicious components detected within the selected time period. Use this metric to understand the volume of malicious component activity identified by Firewall.
Components Waived
This metric displays the total number of components waived within the selected time period. Use this metric to understand how often components are allowed through waiver activity.
Avg Quarantine Time
This metric displays the average amount of time components remain in quarantine within the selected time period. Use this metric to understand how long quarantined components typically remain unresolved.
Sonatype Firewall Activity Over Time
This chart shows daily counts of evaluated, quarantined, and malicious components over the selected period. Use this chart to review changes in Firewall activity over time, including evaluated components, quarantined components, and malicious components.
Quarantine Reasons
This chart shows the distribution of quarantined components by reason. Use this chart to understand how quarantined components are distributed by quarantine reason.
Note: Components categorized as Other are blocked for policy reasons that do not fall under the standard Security, Quality, or License categories. Examples may include proprietary packages, unsupported sources, unidentifiable components, or other organization-specific policy rules.
Components categorized as Null were quarantined, but the policy reason was not captured in the event. These components are included to ensure the Quarantine Reasons chart reconciles with the total Components Quarantined count.
Malicious Threat Categories
This chart shows the distribution of quarantined threats by category. Use this chart to understand how malicious components are categorized by quarantine type.
Note: Components categorized as Null were blocked by a standard policy rule and were not identified as malware. A threat category is assigned only when active malware, such as Trojan, Hijack, or Brandjack, is detected.
Component Risk Classification
The Component Risk Classification table provides component-level details for quarantine and threat classification. The table includes:
- Component Name: Name of the component associated with the quarantine record.
- Quarantine Reason: Reason the component was quarantined.
- Threat Type: Threat classification associated with the component, when available.
- Integrity Quarantine Score: Integrity quarantine score associated with the component, when available.
Note: A Null Threat Type means no malware threat type was identified. The component was quarantined by policy-based rules rather than malware detection.
A Null Integrity Quarantine Score means no integrity quarantine score is available because an integrity assessment was not performed or is not applicable.
For more information about integrity ratings and how they are applied to components, see Release Integrity.
Use this table to review component-level quarantine details and associated threat information.
Quarantine Response Performance
This chart shows how quickly quarantined components are resolved. Use this chart to understand how long components remain in quarantine before resolution.
Waiver Activity Over Time
This chart shows daily counts of waiver activity over the selected period. Use this chart to review trends in auto waivers, manual waivers, and total waivers over time.
Waivers
The Waivers table provides details about waived components within the selected time period. The table includes:
- Threat Level: Severity level assigned to the waived component.
- Policy Name: Name of the policy associated with the waiver.
- Component Name: Name of the component associated with the waiver.
- Created Date: Date when the waiver was created.
- Waiver Expiry Date: Date when the waiver expires.
Use this table to review waived components and associated policy details.
Troubleshooting
Problem: Clicking on the browser Refresh button may give you the following error:
Solution: Click the Back button on your browser, from the page where you see this error, to go back to the Enterprise Reporting landing page. Select the dashboard you want to view to reload the visualizations.
To refresh the page, click the refresh icon on the top right instead of the browser Refresh button.
Problem: No data visible on the dashboard or any other issues with the dashboard.
Solution: Click Copy to Support Info to Clipboard and contact Support with this information.