Skip to content

Threat geo activity

The Threat geo activity report shows threats of certain types, listed by source or destination country, that have been blocked by a specific firewall.

The types of threat include those detected by the following firewall modules:

  • ATP
  • Antivirus
  • IPS
  • Zero-day protection

The numbers relate to threats that have been blocked and have caused a warning alert.


Select the time period for which you want to view details. Threats from the last 24 hours are shown by default.


In the chart area, you can select one of the following chart types:

  • World map that highlights the top 10 countries, by number of threats
  • Globe that highlights the top 10 countries, by number of threats

If you hover the mouse pointer over one of the circles on the chart, the data values are shown next to the pointer.

If you change which threat type is shown on the y axis of the chart, the sizes of the circles vary depending on the number of threats of that type in that country. For example, if you select Antivirus, circles that represent a higher number of antivirus threats are bigger.

You can move the map or the globe in any direction by dragging it with the mouse.


In the Source Country column, the Reserved country includes source or destination IPs that are private. Such IPs do not enable the actual source or destination country to be identified.