Interface Utilization vs. Flow Analysis Interface utilization is the calculated percentage utilization at the interface using SNMP polled data from the IF-MIB (Figure 2) and this is presented as inbound and outbound utilization in Entuity (Figure 1). Figure 1 Interface Utilization and key metrics
Figure 2 Interface statistics in the ifxtabe of the IF MIB Flow Analysis on the other hand is the analysis of flow data sent from a device to a flow collector, this is separate from SNMP management of interfaces. An example of flow is Cisco s NetFlow of which the basic output is a flow record. There are different formats for flow records such as; Netstream v9, sflow v4, sflowv5, JFlow etc. Flow data can be broken down by application, hosts etc. for analysis in Entuity. Figure 3 below is an example of Entuity s Flow Analysis by Application. Figure 3 Entuity Flow Analysis by Application
Flow Analysis You must configure devices to forward their flow information to the Entuity server you want to act as the flow collector. For a server to start collecting flow data from a device an Entuity server must manage that device, so you would usually configure the device to forward its flow data to its managing Entuity server. Figure 4 illustrates devices sending flow data to Entuity. Figure 4 Devices send flow data to Entuity However Entuity separates the flow receiving, data collection and processing from management of the device, which for Entuity IFA Premium allows you to assign flow data received by one server to a second server that acts as a master flow collector. A device would usually export its data to one Entuity flow collector, but they can potentially export to two. Entuity IFA can collect flow data from devices that use either 16-bit or 32-bit interface indexing, from devices running a supported flow version: NetFlow v5. Sampled NetFlow v5. NetFlow v6. NetFlow v7. NetFlow v9, support for the most commonly used templates. Sampled NetFlow v9. IPFIX, comparable support to that delivered for NetFlow v9. Netstream v5. Netstream v9.
sflow v4. sflowv5. JFlow, for Juniper VMware NSX based flows containing VXLAN information. There are two versions of Flow Analyzer in Entuity, Integrated Flow Analyzer and Integrated Flow Analyzer Premium. Integrated Flow Analyzer The Entuity Integrated Flow Analyzer (IFA) is a short time span diagnostic and troubleshooting tool. It avoids the burden of heavy data gathering, synthesis, and storage, whilst still delivering the facility to characterize and understand IP traffic. Entuity IFA integrates flow-based performance data in the Entuity web UI alongside Entuity s traditional elemental performance metrics. You can identify network congestion, applications consuming high percentages of bandwidth, and the source and destination of network traffic. IFA allows for: Collection of flow data from its own local collector. Collection and storing of data with a granularity of five minutes. Data to be retained for one month. Storing of flow data in a compressed, and also in its uncompressed form by disabling deephemeralisation. IFA delivers: Data samples of five minutes, one hour, six hours and daily. Analysis of data with ten available breakdowns, for example. Four types of chart, line, bar, pie and stacked area. Integrated Flow Analyzer Premium Integrated Flow Analyzer Premium (IFA Premium) is a separately licensed module available with Entuity. IFA Premium extends the performance of Entuity IFA, providing greater flow collection and storage capabilities, with more refined presentation and filter control. IFA Premium allows for: Management of flow data collection on remote servers, the number of remote collectors is defined through the IFA Premium license. Collection and storing of data with a granularity of one minute. You must activate this collection through the flow section in entuity.cfg. Data to be retained by more than one month. You can amend data retention through the flow section in entuity.cfg. IFA Premium delivers an enhanced user interface which allows for: Entering From and To date/time for data analysis. Analysis of data by conversation, i.e. both source and destination IP addresses are considered, through a new Top Conversations breakdown.
Definition of Custom Breakdowns, through which you can analyze flow data by an arbitrary combination of data types, for example source IP address, destination IP address, source port, destination port, host IP address, interface, application, protocol, QoS class. Definition of custom data types, whose members, are defined in terms of the available raw data types. This is synonymous with custom groups and group based analysis.