Interface Utilization vs. Flow Analysis

Similar documents
Advanced Application Reporting USER GUIDE

sflow Agent Contents 14-1

Monitoring network bandwidth on routers and interfaces; Monitoring custom traffic on IP subnets and IP subnets groups; Monitoring end user traffic;

Troubleshooting Tools. Tools for Gathering Information

NetFlow Traffic Analyzer

NetFlow Traffic Analyzer

DNS Server Status Dashboard

FlowMonitor for WhatsUp Gold v16.3 User Guide

NetFlow Traffic Analyzer

Trisul Network Analytics - Traffic Analyzer

Subscriber Data Correlation

Server Status Dashboard

NetFlow Traffic Analyzer

Introduction to Netflow

Traffic Flow Measurements within IP Networks: Requirements, Technologies and Standardization

Network Management and Monitoring

Table of Contents. iii

plixer Scrutinizer Competitor Worksheet Visualization of Network Health Unauthorized application deployments Detect DNS communication tunnels

System Requirements. Things to Consider Before You Install Foglight NMS. Host Server Hardware and Software System Requirements

Configuring Data Collection Manager

Introduction... 2 Assumptions... 2

This chapter provides information to configure Cflowd.

Configuring AVC to Monitor MACE Metrics

IMC Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP

NetFlow Optimizer. Overview. Version (Build ) May 2017

HPE IMC NTA MPLS VPN Traffic Analysis Configuration Examples

Exam Name: Riverbed Certified Solutions Professional - Network Performance Management

IMC Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP

Using Centralized Security Reporting

How to Export sflow from a Cisco ASR 9k

DNS Server Status Dashboard

Scrutinizer Flow Analytics

SOLARWINDS ORION 5 DAY COURSE

Application Note Creating a Composite Report For Managed Hosts 12-Oct-2016 Revision 1.0 Compiled by: Larry Balon

Unified Networks Administration & Monitoring System Specifications : YM - IT. YM Unified Networks Administration & Monitoring System

Configuring Application Visibility and Control

Configuring Data Export for Flexible NetFlow with Flow Exporters

Stager. A Web Based Application for Presenting Network Statistics. Arne Øslebø

NetFlow Basics and Deployment Strategies

The ehealth Traffic Accountant Reporting Application

FlowIntegrator. Integrating Flow Technologies with Mainstream Event Management Systems. Sasha Velednitsky

CONTENTS IN DETAIL ACKNOWLEDGMENTS INTRODUCTION 1 1 FLOW FUNDAMENTALS 9 2 COLLECTORS AND SENSORS 21

Using the Cisco NAC Profiler Endpoint Console

WhatsUp Gold Getting Started Guide v16.4

All Events. One Platform.

Using NetFlow Filtering or Sampling to Select the Network Traffic to Track

Monitoring and Analysis

RingCentral QoS Reports User Guide

Centerity Monitor User Guide

Network Operations Analytics

Installing vrealize Network Insight

Managing Reports, Dashboards, and Views

Getting Started. SNMPc OnLine. Version 12.10, March Castle Rock Computing

SteelCentral NPM. NetProfiler, NetShark, Flow Gateway & Packet Analyzer. December 2015

Riverbed SteelCentral vs. Fluke Networks

The Status of IPv6 Network Management

Flow-based Accounting: Applications and Standardisation

Monitor Application Health

Entuity Network Monitoring and Analytics 10.5 Server Sizing Guide

Managing Cisco QoS Using ehealth

Monitoring Dashboard CHAPTER

Compare Security Analytics Solutions

MarkLogic Server. Monitoring MarkLogic Guide. MarkLogic 8 February, Copyright 2015 MarkLogic Corporation. All rights reserved.

WhatsUp Gold Wireless v16.4

Configuring sflow. Information About sflow. sflow Agent. This chapter contains the following sections:

Optimizing Outlook Anywhere with Juniper WXC

XO Stats: User Guide. Monitor your circuit performance, troubleshoot, and plan future network capacity requirements

Real-Time Network Utilization And Bandwidth Monitoring

IP-SIP Telco Dashboard & Network Analytics Software User Guide

IP Access List Overview

Using NetFlow Sampling to Select the Network Traffic to Track

Monitoring individual traffic flows within the ATLAS TDAQ network

SCA Reporter Templates

Monitoring with the Multicast Manager Tool

Navigating Cisco Prime Internetwork Performance Monitor Tasks in LMS 4.1

Installing vrealize Network Insight. VMware vrealize Network Insight 3.3

Generate Reports to Monitor End-user Activity

Common Services Platform Collector Overview

Network and SLA Monitoring Guide Release 7.3

CA Network Flow Analysis

Configuring Data Export for Flexible NetFlow with Flow Exporters

Flexible NetFlow - MPLS Support

WhatsUp Gold v16.0 Wireless User Guide

IBM Network Performance Insight Document Revision R2E1. Using Network Performance Insight IBM

NETWORK FLOW ANALYSIS

Cisco Service Control Business Intelligence Solution Guide,

vrealize Operations Management Pack for NSX for vsphere 2.0

NOCTION. Intelligent Routing Platform Lite Self-Deployment Guide. Intelligent Routing Platform. Lite (free version)

Configuring NetFlow. Information About NetFlow. Send document comments to CHAPTER

It s Flow Time! The Role and Importance of Flow Monitoring in Network Operations and Security

Installing vrealize Network Insight. VMware vrealize Network Insight 3.6

Running Reports CHAPTER

NetFlow and NetFlow Data Export.

Data Collection and Background Tasks

vrealize Operations Management Pack for NSX for Multi-Hypervisor

Prime Performance Manager Overview

ehealth Integration for Lucent Application Brief

RIPE75 - Network monitoring at scale. Louis Poinsignon

10 BEST PRACTICES TO STREAMLINE NETWORK MONITORING. By: Vinod Mohan

ExtraHop 6.2 Web UI Guide

Transcription:

Interface Utilization vs. Flow Analysis Interface utilization is the calculated percentage utilization at the interface using SNMP polled data from the IF-MIB (Figure 2) and this is presented as inbound and outbound utilization in Entuity (Figure 1). Figure 1 Interface Utilization and key metrics

Figure 2 Interface statistics in the ifxtabe of the IF MIB Flow Analysis on the other hand is the analysis of flow data sent from a device to a flow collector, this is separate from SNMP management of interfaces. An example of flow is Cisco s NetFlow of which the basic output is a flow record. There are different formats for flow records such as; Netstream v9, sflow v4, sflowv5, JFlow etc. Flow data can be broken down by application, hosts etc. for analysis in Entuity. Figure 3 below is an example of Entuity s Flow Analysis by Application. Figure 3 Entuity Flow Analysis by Application

Flow Analysis You must configure devices to forward their flow information to the Entuity server you want to act as the flow collector. For a server to start collecting flow data from a device an Entuity server must manage that device, so you would usually configure the device to forward its flow data to its managing Entuity server. Figure 4 illustrates devices sending flow data to Entuity. Figure 4 Devices send flow data to Entuity However Entuity separates the flow receiving, data collection and processing from management of the device, which for Entuity IFA Premium allows you to assign flow data received by one server to a second server that acts as a master flow collector. A device would usually export its data to one Entuity flow collector, but they can potentially export to two. Entuity IFA can collect flow data from devices that use either 16-bit or 32-bit interface indexing, from devices running a supported flow version: NetFlow v5. Sampled NetFlow v5. NetFlow v6. NetFlow v7. NetFlow v9, support for the most commonly used templates. Sampled NetFlow v9. IPFIX, comparable support to that delivered for NetFlow v9. Netstream v5. Netstream v9.

sflow v4. sflowv5. JFlow, for Juniper VMware NSX based flows containing VXLAN information. There are two versions of Flow Analyzer in Entuity, Integrated Flow Analyzer and Integrated Flow Analyzer Premium. Integrated Flow Analyzer The Entuity Integrated Flow Analyzer (IFA) is a short time span diagnostic and troubleshooting tool. It avoids the burden of heavy data gathering, synthesis, and storage, whilst still delivering the facility to characterize and understand IP traffic. Entuity IFA integrates flow-based performance data in the Entuity web UI alongside Entuity s traditional elemental performance metrics. You can identify network congestion, applications consuming high percentages of bandwidth, and the source and destination of network traffic. IFA allows for: Collection of flow data from its own local collector. Collection and storing of data with a granularity of five minutes. Data to be retained for one month. Storing of flow data in a compressed, and also in its uncompressed form by disabling deephemeralisation. IFA delivers: Data samples of five minutes, one hour, six hours and daily. Analysis of data with ten available breakdowns, for example. Four types of chart, line, bar, pie and stacked area. Integrated Flow Analyzer Premium Integrated Flow Analyzer Premium (IFA Premium) is a separately licensed module available with Entuity. IFA Premium extends the performance of Entuity IFA, providing greater flow collection and storage capabilities, with more refined presentation and filter control. IFA Premium allows for: Management of flow data collection on remote servers, the number of remote collectors is defined through the IFA Premium license. Collection and storing of data with a granularity of one minute. You must activate this collection through the flow section in entuity.cfg. Data to be retained by more than one month. You can amend data retention through the flow section in entuity.cfg. IFA Premium delivers an enhanced user interface which allows for: Entering From and To date/time for data analysis. Analysis of data by conversation, i.e. both source and destination IP addresses are considered, through a new Top Conversations breakdown.

Definition of Custom Breakdowns, through which you can analyze flow data by an arbitrary combination of data types, for example source IP address, destination IP address, source port, destination port, host IP address, interface, application, protocol, QoS class. Definition of custom data types, whose members, are defined in terms of the available raw data types. This is synonymous with custom groups and group based analysis.