FILTER > LOOK UP
Available Languages:
English
Use this tool to find a specific host or application
in the database.

Click on the Applications icon to see the top applications
being utilized by this host on this device.
This icon indicates the Destination of the conversation.
This icon indicates the Source of the conversation.
NOTE: This utility searches inbound traffic only on all interfaces of the
selected Flow Device.
Use this tool to find a host or protocol on any/all of the devices (i.e. switches and routers)
that Scrutinizer is receiving NetFlows from.
IMPORTANT NOTE ABOUT AGGREGATION AND SEARCHING:
Scrutinizer saves a tremendous amount of NetFlow information. When searching beyond
"Last 1 hour summary" etc, conversation aggregation may result in data not showing up.
- 1 minute intervals (e.g. Last 1 hour summary) tables contain 100% of all netflow received
- 5 minute intervals (e.g. Last 5 hours summary) tables and less granual tables (e.g. 2 hour
tables - "Last 10 days summary") contain the top 2000-10000 conversations per interval per
flow device. Although this is generally enough, sometimes data expected is aggregated out of
the tables.
- If the host or protocol being searched on wasn't saved in the top conversations
(e.g. top 5000 conversations) by the stored proceedures, the query will fail to find the
data that was transmitted at that time. If the quary fails, try a query which searches
less time. The data targeted has a better chance of not being aggregated out by the storing
engine.
- Why Aggregate? Without aggregation, the tables get very large, the queries take
too long and some customers start complaining about performance.
- To increase the amount of conversations saved per interval, visit
Settings -> Configuration.
- Most periphery (i.e. non core routers) send very little NetFlow and in most cases Scrutinizer will
generally save all of the data. In many cases Scrutinizer will find the host/application on
lower volume netflow devices. Again if necessary, try searching within different time frames
to gain the desired results.
Searching Criteria
- Search By: Select Applications or Users (i.e. Host)
- NetFlow Device: Select a specific switch/router
- Search For: Specify the Host or Application to be searched for
- Filter: Click to launch the query
- Search Results: All of the devices the Host/Application was found on will be listed below
A popup window will appear with the data for the desired time frame.

Click on the Conversation icon
to identify the interface the
host comes in on.

Available Languages:
English