<-

FLOGGING > VIEW

Available Languages: English

Overview

A flog is the raw flow on a specific user or application. Click on this icon to view the most recent 1000 individual conversations involving a host or protocol for the current hour.

The FLOG VIEWER displays all collected data for the host/protocol from ALL interfaces on the router. It is not limited to flogs on the interface being viewed prior to launching the FLOG VIEWER. To see the latest flog entries, continually click the "Refresh" button to see the window refresh with the latest flog entries in real time.

REMEMBER: NetFlow is a summary of conversations, it time stamps when the conversation ended or when the router summarized it.

NOTE: If referencing the SNMP information on the interfaces the flog was captured on would be helpful, click on the wrench icon in the upper right hand corner.

Topics

top

Similar to packet capturing, flogs are basically conversation captures of everything for:

Columns of this Page

The columns of the flog view:

User/Host FLOG
When viewing a User FLOG, look for patterns in the App/Direction. This can be helpful when trying to identify abnormal traffic. Some protocols are generally not used by average end user computers.

Application FLOG
When viewing an Application FLOG, pay attention to the source and destination of the conversations. This can be helpful when trying to identify abnormal traffic. For example, users typically only communicate with the mail server using SMTP, POP3, HTTP and a few other protocols.

IMPORTANT: Keep in mind that NetFlow is based on when the conversation ends (i.e. a 16M conversation that took 7 Minutes before it ends will show up in a single second). What can be done to reduce this problem? The Cisco command below breaks up long-lived flows into 1-minute segments. You can choose any number of minutes between 1 and 60; if you leave the default of 30 minutes you will get spikes in your utilization reports.
Command to type: ip flow-cache timeout active 1

Click Here to learn more on how to configure NetFlow on a router or switch.

Would you like to see a feature added to Scrutinizer? Click Here and tell us about your feature request.

Next Topic: Vitals

Available Languages: English