Available Languages: English
A flog is the raw flow on a specific user or application.
Click on this
icon to view the most recent 1000 individual conversations
involving a host or protocol for the current hour.
The FLOG VIEWER displays all collected data for the host/protocol from ALL interfaces on the router. It is not limited to flogs on the interface being viewed prior to launching the FLOG VIEWER. To see the latest flog entries, continually click the "Refresh" button to see the window refresh with the latest flog entries in real time.
REMEMBER: NetFlow is a summary of conversations, it time stamps when the conversation ended or when the router summarized it.
NOTE: If referencing the SNMP information on the interfaces the flog was captured
on would be helpful, click on the wrench icon
in the upper right hand corner.
Similar to packet capturing, flogs are basically conversation captures of everything for:
The columns of the flog view:
User/Host FLOG
When viewing a User FLOG, look for patterns in the App/Direction. This can be helpful when trying
to identify abnormal traffic. Some protocols are generally not used by average end user computers.
Application FLOG
When viewing an Application FLOG, pay attention to the source and destination of the conversations.
This can be helpful when trying to identify abnormal traffic. For example, users typically only
communicate with the mail server using SMTP, POP3, HTTP and a few other protocols.
IMPORTANT: Keep in mind that NetFlow is based on when the conversation
ends (i.e. a 16M conversation that took 7 Minutes before it ends will show up in a single second).
What can be done to reduce this problem? The Cisco command below breaks up long-lived flows
into 1-minute segments. You can choose any number of minutes between 1 and 60; if you leave
the default of 30 minutes you will get spikes in your utilization reports.
Command to type: ip flow-cache timeout active 1
Click Here to learn more on how to configure NetFlow on a router or switch.
Would you like to see a feature added to Scrutinizer? Click Here and tell us about your feature request.
Next Topic: Vitals
Available Languages: English