Searching for mobile users/MAC addresses in Reporter


This article applies to:

  • Enterprise Reporter
  • Security Reporter

Question:

  • How do I run a report on mobile users/MAC addresses?

Procedure:

There isn't a specific column in the Realtime Traffic Log for the MAC address, and it doesn't appear in the IP address field, as you might expect.

Basically, the MAC address is appended to the username in the "Username" field.

In the Realtime Traffic Log, the field located between the IP address and the date is the "Username" field.

So, in the log entry below...

10.0.0.107,Teacher 00:0b:db:6b:2a:87, 2010/04/15,16:00:03, BNL,0,3,, http://WWW.BOOKADVENTURE.COM/ ,http://bookadventure.com/

The Username would be: "Teacher 00:0b:db:6b:2a:87"

To find a specific mobile user, you should first find out what the user's traffic "looks like" in the traffic log, so that you know what username to search for.

You can then go through the Custom Report Wizard in the Reporter and enter this in the Username field:

e.g.

Teacher 00:0b:db:6b:2a:87

Or, you can use the "%" wildcard character, for example:

%Teacher%

%00:0b:db:6b:2a:87%

 

Notes:

Screenshot included

 

 


Last Modified 6/8/2010.
https://support.trustwave.com/kb/KnowledgebaseArticle13739.aspx