Observer GigaFlow

Documentation

Table of Contents

Observer GigaFlow Documentation

Documentation > Reference Manual for GigaFlow > Profiling

Profiling

The Profiling main menu item has three options: Realtime Overview, Event Dashboard and Traffic Groups.

Profiles help you to understand the normal behaviour of your network. For more, and to create profiles, go to Configuration > Profiling.

Realtime Overview

Profiling > Realtime Overview

The Realtime Profiling Status shows realtime data on defined Profilers. The display updates every 5 seconds and shows:

  • Profiler: this is the defined profile.
  • Clients: the number of connected devices.
  • Hits: the number of flow records that have matched the allowed flows.
  • Exceptions: the flow records for this profile that have deviated from the ideal, or Allowed, profile. See Configuration > Profiling.

Profiling Events

Located at Profiling > Profiling Events.

The Profiling Event Dashboard gives an overview of profile events.

Figure: The Profiling Events page

The profiling event dashboard.

Reporting Period

At the top of the page you can set both the reporting period and resolution, from one minute to 4 weeks.

Profiles

This infographic shows a timeline of the number of events with the profile(s) involved. Circle diameters represent the number of events. The peak number of events in the timeline for each profile are highlighted in red.

Severities

This infographic shows a timeline of the number of events along with their estimated severity level(s). Circle diameters represent the number of events. The peak number of events in the timeline for each severity level are highlighted in red.

Event Entries

Event Entries is dynamically generated; you must click Click To Load to populate the table. The Event Entries table gives a breakdown of profile events with the following entries:

  • The unique event ID number.
  • The time at which event occurred.
  • The category or profile name.
  • The severity of the event as a percentage.
  • The source IP address.
  • The target IP address.
  • The application, user defined if it exists. See also Configuration > Profiling and Flow Details.
  • Any information other error/status message, e.g. Profiler Exception.

A drop-down selector lets you choose the number of the most events to display.

Flow Details

To access a detailed overview of any flow, click on the adjacent Drill Down icon Drill down icon.. This provides a complete overview of that flow, listing:

  • The source address, a link to search forensics and any associated blacklists.
  • Source MAC address.
  • Destination address, a link to search forensics and any associated blacklists.
  • Destination MAC address.
  • Source port.
  • Destination port.
  • Appid: the application ID is a unique identifier for each application.
  1. In GigaFlow, Appid is a positive or negative integer value. The way in which the Appid is generated depends on which of the 3 ways the application is defined within the system. Following the hierarchy outlined in Configuration > Profiling -- Apps/Options -- Defined Applications, a negative unique integer value is assigned if (1) the application is associated with a Profile Object or (2) if it is named in the system. If the application is given by its port number only (3), a unique positive integer value is generated that is a function of the lowest port number and the IP protocol.
  • Application. See Appid, above, and Configuration > Profiling.
  • Number of packets in flow.
  • Number of bytes.
  • User.
  • Domain.
  • Fwevent. See
  • Fwextcode.
  • Profile, e.g. PCs.
  • Net device IP address, name and number of flows.
  • In-Interface.
  • Out-Interface.

See Glossary for more about flow record fields used by GigaFlow.

See also Search for instructions to access the Graphical Flow Mapping feature.

Filtered Views

By clicking any Category, Severity, Source IP or Target IP in the Event Entries table, you will be taken to a version of the Events Dashboard filtered for that item.

See Dashboards > Events for an overview of the structure of this page.

(Existing) Traffic Groups

Overview

Located at Profiling > Traffic Groups.

Traffic groups are subnet and IP range aliases.

  • You can assign a name to a subnet or IP range.
  • GigaFlow will collect data associated with this range.
  • A traffic group can be a subset of another traffic group, e.g. a traffic group spans 172.1.1.0 - 172.1.1.255 and a second traffic group is defined as 172.1.1.80 - 172.1.1.122.

Top Traffic Groups Sources (Last Hour v Last Week Hour)

This graph shows the top 10 destination IPs over the past hour.

Top Traffic Groups Destinations (Last Hour v Last Week Hour)

This graph shows the top 10 destination IPs over the past hour.

Top Traffic Groups Sources (Last Hour v Week Last Week Hour)

This graph shows the top 10 source IPs over the past hour.

Top Traffic Groups Destinations (Last Hour v Week Last Week Hour)

This graph shows the top 10 destination IPs over the past hour.

Summary Source Traffic Groups

This graph shows the traffic associated with traffic groups over the past hour. The information displayed includes:

  • Avg Bits/s: average traffic per second per application.
  • Percentage: this is the proportion of all traffic over the past hour seen by a particular traffic group.
  • Position relative to the same hour last week: this is the percentage increase or decrease in traffic per second per traffic group compared with the same hour last week.

When more than ten traffic group are registered, the full list can be displayed by clicking the drill down icon. This displays a tabular version of all the data, with a CSV export option.

Summary Destination Traffic Groups

This graph shows the destination traffic associated with traffic groups over the past hour. The information displayed includes:

  • Avg Bits/s: average traffic per second per application.
  • Percentage: this is the proportion of all traffic over the past hour seen by a particular traffic group.
  • Position relative to the same hour last week: this is the percentage increase or decrease in traffic per second per traffic group compared with the same hour last week.

When more than ten traffic group are registered, the full list can be displayed by clicking the drill down icon. This displays a tabular version of all the data, with a CSV export option.