Previous Topic: Flow Forensics Reports

Next Topic: Work with Flow Forensics Reports

Flow Forensics Report Types

The following topics describe the available Flow Forensics reports.

Address Report Group

Address Pairs Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of each source and destination address pair.

Destination Address Peer Count Report

Displays the following information about each traffic destination:

Destination Addresses Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of each traffic destination.

Source Address Peer Count Report

Displays the following information about each traffic source:

Source Address Peer Count with Destination Port Report

Displays the following information about each traffic source:

Source Addresses Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of each source address.

ICMP Report Group

Bad IP Headers Report

Displays the source address and flow count of each bad IP header--each IP header that failed the checksum.

Fragmentation Required and DF Flag Set Report

Displays the following information about packets that require fragmentation--packets that had unreachable hosts or that were flagged Fragmentation Needed and Don't Fragment:

ICMP Traffic Summary Report

Summarizes the Internet Control Message Protocol (ICMP) types and codes that occurred. The report contains the following information:

Ping Conversation Pairs Report

Displays the following information about ping requests:

Ping Destinations Report

Displays the following information about ping request destinations:

Ping Sources Report

Displays the following information about ping request sources:

Traceroute Requests by Destination Report

Displays the following information about traceroute request destinations:

Traceroute Requests by Source Report

Displays the following information about traceroute request sources:

Traceroute Requests Pairs Report

Displays the following information about each traceroute address pair:

TTL Expired in Transit Report

Displays the following information about data that met or exceeded the Time To Live (TTL) threshold:

Unreachable Destination by Source Report

Displays the following information about sources that tried to connect with unreachable destinations:

Unreachable Destination Networks Report

Displays the following information about unreachable destinations:

Unreachable Destinations Report

Displays the following information about sources and unreachable destinations:

MAC Report Group

Destination MAC Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count on each destination Media Access Control (MAC) address.

MAC Pairs Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count on each pair of source and destination MAC addresses.

Source MAC Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count on each source MAC address.

MPLS Reports

MPLS Labels Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of traffic that had a unique combination of the following values:

Network Reports Group

Autonomous System Pairs Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic between a pair of source and destination autonomous systems.

Autonomous System Pairs (with Destination Network) Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic that had a unique combination of the following values:

Destination Autonomous Systems Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each destination autonomous system.

Destination Networks Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of traffic on each destination network and subnet.

Network Pairs Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each pair of source and destination network subnets.

Network Pairs (with ToS) Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each network pair that had a unique combination of the following values:

Next Hops Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic for each next-hop address.

Source Autonomous Systems Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each source autonomous system.

Source Networks Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each source network and subnet.

TCP Resets Report

Displays the TCP reset count of traffic on each source and destination address pair.

QOS Report Group

Differentiated Services Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the traffic flow count for each DiffServ code point (DSCP) value.

Types of Service Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the traffic flow count for each Type of Service (ToS).

Session Report Group

Client-Server Sessions

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of each session that had a unique combination of the following values:

Conversation Sessions Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count and cumulative flow duration of each conversation session that had a unique combination of the following values:

Conversations Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic for each IPv4 address pair that had a unique combination of the following values:

Conversations (IPv6) Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic for each IPv6 address pair that had a unique combination of the following values:

Conversations (with Interfaces)

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of each conversation that had a unique combination of the following values:

Destination Applications Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic that had a unique combination of the following values:

Destination Endpoints Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic that had a unique combination of the following values:

Protocols Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic that had a unique IP protocol.

Server-Client Sessions Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of each traffic session that had a unique combination of the following values:

Source Applications Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of each traffic session that had a unique combination of the following values:

Source Endpoints Report

Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of each traffic session that had a unique combination of the following values:

TCP Reports

TCP Flags Report

Displays volume, rate, and percent of total inbound bytes/packets, as well as the flow count of traffic for each TCP flag.

VLAN Report Group

Destination VLANs Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of traffic on each destination VLAN.

Source VLANs Report

Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of traffic on each source VLAN.

VLAN Pairs Report

Displays the volume, rate, and percent of total bytes in/packets in, as well as the flow count of traffic on each source and destination VLAN pair.