Smart Logging Telemetry (SLT) is one of the latest NetFlow v9 exports from Cisco. This new export is very unique because the data in the flows isn’t just used for traditional NetFlow reporting such as top hosts or top applications.  The hardware (e.g. Catalyst 3XXX) supporting this technology is actually helping to secure today’s networks by performing a type of network behavior analysis on the traffic trying to traverse the switch fabric.

Smart Logging and Telemetry:

  • Cisco Smart Logging and Telemetry (SLT): This new technology exports NetFlow messages for traffic that is associated to a specific event on a switch (for example, an event triggered by an ACL-permitted or -denied packet).
    Smart Logging Telemetry Report
  • Layer 2 features such as Dynamic ARP Inspection, Dynamic Host Configuration Protocol (DHCP) Snooping, IP Source Guard, and Port ACLs can now log events (such as policy violations) to an external analyzer device by exporting event information and portions of packets over a NetFlow v9 transport.
    Smart Logging Telemetry NetFlow Packets
  • Available on the Catalyst 3750, 3560, 3750E, 3560E, 3750x, 3560x
    Smart Logging Telemetry NetFlow Switches

The above support is shipping with our next major release.

Michael

Michael

Michael is the Co-Founder and the product manager for Scrutinizer Incident Response System. He can be reached most hours of the day between work and home. He enjoys many outdoor winter sports and often takes videos when he is snowmobiling, ice fishing or sledding with his kids. Cold weather and lots of snow make the best winters as far as he is concerned. Prior to starting Somix and Plixer, Mike worked in technical support at Cabletron Systems, acquired his Novell CNE and then moved to the training department for a few years. While in training he finished his Masters in Computer Information Systems from Southern New Hampshire University and then left technical training to pursue a new skill set in Professional Services. In 1998 he left the 'Tron' to start Somix which later became Plixer. Feel free to email him.

Related

Big Data

Sankey Flow Graph

One of the greatest benefits of NetFlow collection for traffic analysis, is we’re provided with the ability to visualize the…