cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1531
Views
0
Helpful
8
Replies

Numbers in reports are completely wrong

cryptochrome
Level 1
Level 1

Hi,

I keep wondering about ESA's reporting. For instance, we currently have about 15.000 emails with malicious URLs in a policy quarantine. This quarantine holds mails for 30 days and then deletes them. If I go to the URL Filter Report and select the last 30 days, it tells me we had 200 mails with malicious URLs. 

Uhm... what?

The same is happening in other areas like the Virus report. 

What gives?

 

8 Replies 8

ppreenja
Cisco Employee
Cisco Employee
Hello,

Policy quarantine usually contains all the emails which are sent via various filters and not only emails with malicious URLs.
Are you sure that only emails with malicious URLs are in your policy quarantine? Please share more information so as to understand your issue better.

Cheers,
Pratham

Hi Pratham,

we have a dedicated policy quarantine for malicious URLs. It holds only email that contain malicious URLs, nothing else. We did this by creating a separate quarantine and then use content filters to quarantine mails with malicious URLs into it. No other content filter or feature stores mails in that particular quarantine. 

Result: That quarantine has thousands of mails in it (past 30 days), while the URL filter report shows only 200 for the same timeframe. 

I seem to remember that someone here on this forum once said that the reporting feature of ESA has a problem, where mails that were already registered as spam will only show in the reports as spam, even if they contained other threats. 

 

Hi ,

Thank you for explaining in detail. I was able to find below cosmetic bug which might be able to answer your query:

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvf36406

I hope this answers your query.

Cheers,
Pratham

Thanks. When will this be fixed?

Hello,

Currently, there is no ETA on the resolution however development team is working on the fix. I would suggest you add yourself to the notifications on the above-shared link so that as soon as the fix is in place you are notified regarding the same.

Cheers,
Pratham

Just curious, are you looking in the new gui, or old gui?

It MIGHT be different in the new gu


Old GUI. We're not using the new GUI yet.

If you have a modern version of ESA, take a look in the new GUI and see if it got fixed there.