Skip to content Skip to main navigation Skip to footer

Cyfin & CyBlock Report Glossary — Report Definitions & Descriptions (Sessions-Based Reporting)

Applies to: Cyfin and CyBlock · A reference to what each standard report shows and when to use it.

Cyfin and CyBlock share the same reporting feature — the same reports, the same paths, and the same metrics in both products. Everything below applies identically to either one. This is the glossary of the standard reports — their definitions / descriptions — reflecting the current sessions-based reporting direction. Sessions are the primary metric in high-level reports; Hits appear at the deepest drill-down. (If you’re looking for the older “Visits” or “Time Online” metrics, see What happened to Visits and Time Online? at the end.)


How to use the reports together

There are two ways in, and most reviews use both in sequence:

  1. Proactive / summary reports survey the whole population — who is most active, which sites and categories dominate. Use these to spot a user ID or a site of interest. (Top Users, Top Web Sites, Site Analysis, Site Audit Summary.)
  2. Session investigation reports take a single user ID of interest and reconstruct exactly what that person did, drilling from a high-level summary down to individual URLs. This is the pathway for a focused review of one user — for example an employee web-activity investigation. (Session Analysis → Session Audit Summary → User Audit Detail.)

A typical review: scan the summary reports, find an ID or site that stands out, then run a session investigation on that specific ID.


Report metrics at a glance

Reports use two metric families, and which one you see depends on the report:

  • Session reports (Session Analysis, Session Audit Summary, User Audit Detail) use Sessions and Session Duration. Session Duration is available only in these reports.
  • All other reports are hit-based — they quantify activity by Hits and Bytes. They no longer include Visits or Time Online; both of those metrics have been retired.

So if you need duration, use a session report; the hit-based summary and detail reports measure activity by hit and byte volume.


Session Investigation Reports — the investigation pathway

These three reports are three levels of detail on the same user and period — you start high and drill down by clicking hyperlinks. Sessions reconstruct scattered firewall/proxy connection records into readable browsing events, filtering out non-human background traffic (OS updates, telemetry, ad trackers) so the report reflects what a person actually did, not raw log volume.

Session Analysis (Level 1 — start here)

A complete summary of one user’s web activity across the full investigation period: every application/site accessed, session counts, session duration, and content categories, with color-coded classifications. Ranked by session count so areas of concern surface first. Clicking an application opens the Session Audit Summary for that site. This is where every investigation begins.

Session Audit Summary (Level 2)

Narrows to one selected application and lists every session the user had on it — session start, session stop, and duration for each, plus the device IP address and category. Shows the pattern of access: how many sessions, how long each lasted, and whether activity clustered at particular times. Clicking a session opens the User Audit Detail.

User Audit Detail (Level 3 — the evidence)

The most granular level: every URL logged during one selected session, in chronological order, with timestamp, category, classification, and full clickable URL. Includes a URL search filter and a Total Denied Requests count. This is the evidentiary foundation for any formal action. Note: the list includes background and site-generated requests, so not every URL is a deliberate click — the session grouping above it is what isolates meaningful activity.


Summary / Proactive Reports

Use these to survey activity and identify who or what to investigate.

Site Analysis

A high-level, hit-based audit of activity from several perspectives — by classification (Acceptable / Unacceptable / Neutral), by category, by group, by user, and by user within each category, measured in hits and bytes. Individual sites are not identified. Good for broad or focused audits of activity volume across the population.

Top Users

Lists the most active users by activity volume (hits, denied hits, and bytes). An excellent screening tool: it surfaces the users with the highest activity so you can drill down or launch a session investigation on those IDs.

Top Web Sites

Lists all accessed sites (domains) with their category, hits, and bytes, sorted by activity volume. Individual user IDs are not shown, but each site links out for further analysis. Highlights the most-accessed sites; inappropriate ones can prompt deeper investigation or blocking.

Site Audit Summary

Lists the top groups and users who accessed a particular site (can be run for more than one site), with hit and byte totals and hourly breakdown, and a link to each user. A quick, summarized look at who is using a given site the most.


Detail & Audit Reports

Targeted deep-dives into a category, a site, search terms, or blocked requests.

Category Audit Detail

A detailed analysis of one selected category (e.g., Pornography): all URLs for each user who accessed that category, plus the top users, groups, and hourly activity within it. Useful for auditing possible misuse concentrated in a specific category.

Site Audit Detail

Focuses on one or more specific sites: every record to those URLs, listed chronologically for all users, with IP address, user, and full URL, plus top-group/user/hourly summaries. A complete view of who accessed a given site and what they did.

Search Term Audit Detail

Shows the search terms users entered on popular search engines (Google, etc.), with IP address, user, date/time, and search engine. A forensic aid — indicates how many search terms were entered and by whom.

Denied Requests

By category, shows which users were denied access to sites or pages during the period. Individual users are identified; specific URLs are not. If web filtering is enabled, this verifies it’s working and flags attempts to reach blocked content.

Denied Requests Detail

The URL-level version: the specific URLs to which each user was denied access, by user, in the requested category. A useful supplement to individual user audits, showing the number and type of blocked requests.


IT / Bandwidth Reports

Focused on network and bandwidth rather than individual behavior.

Network Information

Total hits, byte trends, and total bytes broken down by classification, category, group, IP address, and hourly activity. No individual users or sites are identified — it keeps the focus on bandwidth, helping admins spot network performance issues.

Site Analysis Bandwidth

Like Site Analysis, but focused on bandwidth consumption instead of hit counts: trend in bytes and total bytes by classification, category, group, user, and user within category. Helps IT manage bandwidth and identify the heaviest users per category.

Top Bandwidth Sites

The top bandwidth-consuming sites for a selected group, each with its category and byte consumption, sorted highest-first. Individual users are not shown. Quickly identifies which sites are driving bandwidth so unwarranted consumption can be investigated or blocked.


Key terms

Session — A period of continuous user activity with a single application/site, reconstructed from the log. Opens at the first qualifying activity and closes after a set inactivity period (commonly 10 minutes), and must meet minimum thresholds to be counted. Session count is the primary metric in high-level reports.

Session Duration — Elapsed time from the first to the last record within a session (HH:MM:SS) — meaningful active time, not raw connection time. Available only in the session reports. It replaces the retired Time Online metric.

Sessions % — A site’s or category’s share of all sessions, shown as a number and a classification-colored bar.

Session Duration % — A site’s or category’s share of total reporting-period time. A site with few sessions can still show a high duration % if those sessions were long.

Hit — A single log record. One page load generates many hits (images, scripts, stylesheets, background requests). Hits are the raw material sessions are built from and appear at the deepest drill-down level, not as a headline metric.

Application / Web Site (App/Site) — A recognized web service grouping all its related domains under one friendly name (e.g., fbcdn.com rolls up under “Facebook”), so reports stay readable.

Category — The product’s content category for a site (e.g., Video Streaming, Auctions/Classifieds, Shopping, News).

Classification — The policy label applied to categories: Acceptable (green), Unacceptable (orange), or Neutral (gray). The category-to-classification mapping is set by your organization’s acceptable-use policy.

Denied Request — A request blocked by your proxy or firewall before reaching its destination. A non-zero count means blocked content was attempted.

Bytes — Volume of data transferred (KB or MB).

Ingestion — Loading raw proxy/firewall log data into Cyfin for a user and period; reporting begins after ingestion completes. By default Cyfin excludes known non-human domains during ingestion; this can be disabled if a full traffic record is needed.

User ID — The network login identifier used to attribute activity to an individual across all reports (e.g., firstname.lastname).


What happened to Visits and Time Online?

Customers on legacy reports may still expect the Visit and Time Online metrics. Both have been retired:

  • Visits have been upgraded to Sessions. Sessions capture a user’s continuous engagement with a site or app, which gives a clearer, more accurate picture than a single-interaction count in today’s dynamic web — where one page pulls content from many servers and mixes in automated background traffic.
  • Time Online has been replaced by Session Duration, which is available only in the session reports.

The hit-based reports (everything outside the session reports) now measure activity by Hits and Bytes — they no longer show Visits or Time Online. Hits and Visits were the right tools for their time; sessions build on that foundation. This is a response to how the web changed, not a correction of past reporting.