Absolute Thresholds

You have the option to set an absolute threshold so that alerts are generated when the threshold is violated, provided that alerts are enabled. Absolute thresholds are applied before probability thresholds.

The following table lists the sensors and units of measure for absolute thresholds.

Sensor

Looks For:

Unit of Measure

Buffer Misses

Pattern in buffer misses

buffer misses

Congestion Sources

Sources of overloading based on ICMP Source Quench

flows

Destination Unreachable Sources

High-volume sources of network, host, or port unreachable messages

host or port unreachable messages

Dropped Packets

Pattern in queue drops

dropped packets

Fragmented Packet Sources

Large sources of fragmented packets

fragmented packets

Frags And Loss Sources

Sources of fragmentation and packet loss

flows

High and Variable Vol-In

Highest-volume and variability destinations

bytes in

High and Variable Vol-Out

Highest-volume and variability sources

bytes out

High Flow Sources

Top sources of data flows

flows

High Packet Fan Out

Sources of the largest fan-out traffic patterns

destination hosts

Incoming Discard Rate

Pattern in incoming discards

discard rate

Incoming Error Rate

Pattern in incoming errors

error rate

Large DNS Packet Sources

Large sources of DNS packets that are larger than normal

flows

Large ICMP Packet Sources

Large sources of ICMP packets that are larger than normal

flows

Non-local Sources

Top sources of non-local traffic

non-local traffic

Packet Load

Pattern in bytes per packet to server

bytes per packet

Previously Null Routed Srcs

Hosts with high volumes of traffic that is no longer null-routed

flows

Refused Sessions

Pattern in refused sessions

percent

Retransmission Time

Pattern in retransmissions

seconds

RST-Only Sources

Highest-volume sources of RST-only flows

flows

SYN/RST-Only Packet Srcs

Highest-volume sources of SYN/RST-only flows

flows

SYN-Only Packet Sources

Highest-volume sources of SYN-only flows

flows

TTL Expired Sources

High-volume sources of TTL expired packets

flows

Voice Call DoS

DoS in voice calls

calls per minute

Voice Call Fan Out

Pattern in fan-out of voice calls

call ratio

Voice Server Distress

Call Server Distress

Volume Weighted Error Ratio