The Network Flow Forensics reports have the following fields.
|
Report |
Src A S |
Dest A S |
Src Network |
Dest Network |
Src Addr |
Dest Addr |
ToS |
Next Hop |
TCP Reset Count |
Bytes |
Rate (Bits) |
% Total (Bytes) |
Flows |
Pkts |
Rate (Pkts) |
% Total (Pkts) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
Autonomous System Pairs |
Y |
Y |
|
|
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Autonomous System Pairs (with Destination Network) |
Y |
Y |
|
Y |
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Destination Autonomous Systems |
|
Y |
|
|
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Destination Networks |
|
|
|
Y |
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Network Pairs |
|
|
Y |
Y |
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Network Pairs (with ToS) |
|
|
Y |
Y |
|
|
Y |
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Next Hops |
|
|
|
|
|
|
|
Y |
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Source Autonomous Systems |
Y |
|
|
|
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
Source Networks |
Y |
|
|
|
|
|
|
|
|
Y |
Y |
Y |
Y |
Y |
Y |
Y |
|
TCP Resets |
|
|
|
|
Y |
Y |
|
|
Y |
|
|
|
|
|
|
|
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic between a pair of source and destination autonomous systems.
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic that had a unique combination of the following values:
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each destination autonomous system.
Displays the volume, rate, and percent of total inbound bytes/packets, as well as the flow count of traffic on each destination network and subnet.
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each pair of source and destination network subnets.
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each network pair that had a unique combination of the following values:
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic for each next-hop address.
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each source autonomous system.
Displays the volume, rate, and percent of total inbound bytes and packets. Also displays the flow count of traffic on each source network and subnet.
Displays the TCP reset count of traffic on each source and destination address pair.
|
Copyright © 2014 CA.
All rights reserved.
|
|