NetFlow Collection

Posted in Cisco AVC, netflow collection on May 19th, 2013 by mike@plixer.com
NetFlow Collection

High volume NetFlow Collection usually can’t be attained by simply placing the NetFlow collector on beefier hardware. It requires understanding of the protocol, the preprocessing necessary to meet the demands of the front end, tweaking memory, optimizing database settings and of course powerful hardware.
Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , ,

Next Generation NetFlow Analyzer: NetFlow Reporting Tools

Posted in IPFIX, NetFlow Analysis, NetFlow Dashboard, NetFlow Reporting on May 6th, 2012 by mike@plixer.com
Next Generation NetFlow Analyzer: NetFlow Reporting Tools

The most advanced Flow technologies today come in the form of (FnF) Flexible NetFlow Reporting and IPFIX Reporting.  Some vendors have renamed these technologies to AppFlow, Cascade Flow, J-Flow and NetStream, however they are usually a near copy of either NetFlow or IPFIX.

List of Next Gen NetFlow / IPFIX Reporting Features

Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , ,

NetFlow Alarming Vs. NetFlow Investigations

Posted in NetFlow, Network Problem Resolution on January 17th, 2011 by mike@plixer.com
NetFlow Alarming Vs. NetFlow Investigations

Can I ask you something?  As the manager of the network I’m sure you and your team end up investigating a lot of potential threats. My question is: what is your guess as to the ratio of NetFlow alarms you investigate from your NetFlow tool to the number of calls you receive from a user on the network complaining about a problem?  In other words, are the canned (i.e. non custom) NetFlow detected alarms more helpful or are your own investigations and user complaints more helpful?

NetFlow Alarms Vs. NetFlow Investigations

The reason I ask is because the lions share of the NetFlow case studies we write regarding NetFlow analysis experiences end up being related to problems found where an application was doing something it didn’t need to be or could be done at a different time of the day. Second to this would be viruses and botnets.  I feel that good reporting and filtering in a NetFlow tool like we find in Wireshark packet analyzer is equally or more important to NetFlow Network Behavior Alarming.  I believe most people would agree that waiting for alarms that tell you the majority of problems on the network is wishful thinking.

I’m a big fan of creating custom behavior watches using saved reports. Many NetFlow Analyzers and this includes the expensive ones, don’t have good filtering and custom alarming abilities. I’ll digress further on this in another blog on NetFlow filtering.

Although our NetFlow tool constantly scans the flows for anomalous activity and alarms for it, most IT professionals using our tools are so busy, that they often only have time to respond to something very obvious in the dash board or generally react to telephone calls. Few people watch the alarm log or even respond to every alert because of the potential for an insignificant issue or they use the alarm log after they find a problem.

Read more »

Michael Patterson
Founder and CEO

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , ,

sFlow vs. NetFlow

Posted in NetFlow, sFlow on October 26th, 2009 by Brian
sFlow vs. NetFlow

We get a lot of questions on this topic. Personally, I generally deflect to some of the stuff we have posted on YouTube. Even though this webcast was recorded using Scrutinizer v6.X, I think the content is still very informative, if you have questions regarding the differences between sFlow and NetFlow collection for network traffic analysis.

 

Read more »

Brian

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , ,

Customizing Scrutinizer can make a huge impact

Posted in Scrutinizer on July 6th, 2009 by Steve
Customizing Scrutinizer can make a huge impact

Did you know that Scrutinizer 6.05 has a custom portal that can be configured to show your company logo and also any message you would like to convey?

Read more »

Steve

For a free 30 day trial of Scrutinizer, Download Now!

Sign up for Advanced NetFlow Training™ coming to a city near you!

Tags: , , , ,