> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 22,043 Events, One Day

> A full 24-hour analysis window, from total parsed events down to unique threat actors, in a single narrative summary

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/XtQuNxdDTqAwCnod/images/case21.png?fit=max&auto=format&n=XtQuNxdDTqAwCnod&q=85&s=0632d633cb234b95ad0603acad4422bf" width="978" height="854" data-path="images/case21.png" />

This is the summary view for the analysis window 2026-08-15 23:59:09 to 2026-08-16 23:59:09: **22,043** total parsed events, down 20% against the prior window, broken down into every category covered elsewhere in this report.

***

## The full chain in one place

Of 22,043 total events, **4,477 (20.31%)** were blocked by Demo Org's own firewall and **1,511 (6.85%)** more were blocked through the checkpoint-ip integration. **16,055 (72.83%)** were permitted. Of that permitted traffic, **1,939 (8.80%)** was flagged and intercepted as malicious after the fact. Across the entire window, **1,723** unique threat actors were identified.

## Why 1,723 doesn't equal the sum of the other actor counts

The severity table elsewhere in this report lists unique IP counts per band that don't add up to 1,723 when summed directly, because a single actor can generate events across more than one severity band or appear in both the blocked and permitted branches during the same window. 1,723 is the deduplicated total across the entire dataset, not a sum of the per-band figures.

## What a -20% change means here

The prior-period comparison is carried at the top level of this summary, not buried in a footnote. A 20% drop in total parsed events changes the denominator every other percentage in this report is measured against, which is why it's surfaced before any of the breakdown figures.

***

Proof of Value engagements produce this exact daily summary against a client's own edge traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
