All

Ziften ZFlow Reporting Support

After analyzing their impressive export, Ziften ZFlow reporting support or Ziften IPFIX support is now supported by our flow collection system. Per their announcement...

Fortiswitch IPFIX Configuration

Today I want to talk a little about the Fortiswitch IPFIX configuration on the Fortiswitch-500. As of version 4.0 MR1 the Fortiswitch-500 can export...

Arista sFlow Configuration

Lately I’ve spoken to a few people in the field that are using Arista switches to get visibility into their networks using sFlow and...

NetFlow Directionality Support : Part 2

This is a continuation of Flow Directionality Support : Part 1 which should be read first. My guess is that a flow collector vendor...

IWAN NetFlow Support

For a while now we have had IWAN NetFlow support built into our network incident response system, which collects and reports on NetFlow, IPFIX,...

Responding to zero day threats using NetFlow

In this blog, I want to talk to you about investigating zero-day attacks. A zero-day attack can be a huge menace on the network, since it can bypass a lot...

Understanding Netflow Traffic Volume

Seeing how much traffic is going over an interface is an integral part of every network professional’s daily routine. This information can be used...

SIEM Market Misrepresenting Their Security Value

If you think that your company’s SIEM is a reasonably good solution for detecting intrusions, your probably less safe than you think. SIEMs rely...

Exchange Monitoring Tool

My colleague Jake recently wrote about Disaster Recovery Monitoring, and about how our Incident Response System, using IPFIX/NetFlow is more helpful then tools that...