> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Events to Actors

> A full traffic flow breakdown showing how parsed events split by enforcement decision, then converge by severity into unique threat actor counts

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/c9Vjcenp_X2kF3QC/images/case12.png?fit=max&auto=format&n=c9Vjcenp_X2kF3QC&q=85&s=47f9cc004faafb6645d5c16dce1eba23" width="2690" height="1280" data-path="images/case12.png" />

This flow diagram traces the same event set through two independent classifications: what the client's own firewall did with the traffic, and what severity OneFirewall assigned to it. The two classifications don't collapse into each other — traffic gets a severity score regardless of whether it was already blocked.

***

## The first split: enforcement decision

Of total parsed events, **72.9%** were passed by Demo Org's firewall and **27.1%** were blocked. This is the enforcement outcome on its own, before severity is factored in.

## Severity within each branch

Both branches are then broken down by the same four severity bands, independent of the enforcement action already taken.

Within the passed branch: **64.0%** of total events were Clean Traffic, with **4.0%** Low, **2.2%** Medium, **0.9%** High, and **1.5%** Critical severity slipping through despite being permitted.

Within the blocked branch: **11.4%** Low, **6.8%** Medium, **3.1%** High, and **5.5%** Critical — meaning most of what Demo Org's firewall blocked was, independently, also scored as malicious by OneFirewall. A small slice, **0.3%**, is labeled Denied (Contributed Value): traffic the firewall blocked that OneFirewall's scoring assessed as clean, cross-validating that portion of the existing rule set rather than flagging it as a gap.

## Convergence into actor counts

On the right, the four severity bands from both branches converge into unique threat actor totals, deduplicated across whatever enforcement decision already applied to their traffic: **513 Low Actors**, **283 Medium Actors**, **120 High Actors**, and **196 Critical Actors**. This is a count of distinct sources at each severity level, not event volume — a single actor can appear in both the passed and blocked branches across different events and still counts once here.

***

Proof of Value engagements produce this same flow breakdown against a client's own traffic. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
