Located at Reports > Forensics.
See Configuration > Reporting for instructions on how to configure and create new report types. See Appendix > Forensic Report Types for a complete description of the different report types.
Forensics allows you granular, filterable reporting on the stored records. GigaFlow records flow posture, i.e. whether or not a flow is flagged as an excepted event, allowing for detailed analysis.
To create a report:
A router - an infrastructure device - has an IP of 192.0.2.1.This router was defined at Configuration > Infrastructure Devices.Choose an Applications report from the report type drop-down menu.Choose Infrastructure Device from the filter drop-down menu.Choose the router from the list of devices and apply the filter by clicking +.
The system will return a graph and/or table with details of:
Queries can be entered directly and quickly using the direct filtering syntax.
Field | Operators | Description | Example |
---|---|---|---|
srcadd | =, != | IP Address that the traffic came from. | srcadd=172.21.40.2 |
dstadd | =, != | IP Address that the traffic went to. | dstadd=172.21.40.3 |
inif | <, =, >, != | ifIndex of the interface through which the traffic came into the router. | inif=23 |
outif | <, =, >, != | ifIndex of the interface through which the traffic left the router. | inif=25 |
pkts | <, =, >, != | Number of packets seen in the flow. | pkts>100 |
bytes | <, =, >, != | Number of bytes seen in the flow. | bytes<10000 |
duration | <, =, >, != | Duration of flow in milliseconds. | duration>100 |
srcport | <, =, >, != | Source IP port of flow. | srcport>1024 |
dstport | <, =, >, != | Destination IP port of flow. | dstport=5900 |
flags | <, =, >, != | TCP Flags of flow. flags=2 i.e. syn only. | Flags=CEUAPRSF |
proto | <, =, >, != | IP Protocol Number/Type. | proto=16 |
tos | <, =, >, != | TOS Marking. tos=104 | //Flash |
srcas | <, =, >, != | Source AS Number. | srcas!=5124 |
dstas | <, =, >, != | Destination AS Number. | dstas!=5124 |
fwextcode | =, != | Forwarding Extended Code. | fwextcode='out-of-memory' |
fwevent | =, != | Forwarding Event. | fwevent!='Flow Deleted' |
tgsource | =, <> | Traffic Group Source. | fwextcode<>'My network 1' |
tgdest | =, <> | Traffic Group Destination. | tgdest<>'Other' |
© Copyright 2019 Anuview. All rights reserved. VIAVI and the VIAVI logo are trademarks of VIAVI Solutions Inc. ("VIAVI"). All other trademarks and registered trademarks are the property of their respective owners. No part of this guide may be reproduced or transmitted, electronically or otherwise, without the written permission of the publisher.
Reproduction and distribution of this guide is authorized for Government purposes only.