Symantec 10268947 User Guide - Page 117

About querying flows, Viewing current flows

Page 117 highlights

Reports and Queries 117 About querying flows Table 9-6 Drill-down-only reports Report Description Flows by source port Flows by destination port Flows by protocol This report lists the source ports of flows found on devices with Flow Status Collection sensor mode enabled. You can generate this report from within the Devices with Flow Statistics report. This report lists the destination ports of flows found on devices with Flow Status Collection sensor mode enabled. You can generate this report from within the Devices with Flow Statistics report. This report lists the protocols of flows found on devices with Flow Status Collection sensor mode enabled. You can generate this report from within the Devices with Flow Statistics report. About querying flows FlowChaser serves as a data source in coordination with Symantec Network Security TrackBack, a response mechanism that traces a DoS attack or network flow back to its source. The FlowChaser database can be queried for flows by port and arbitrary address. The Network Security console displays both current flow data and exported flow data, and provides secondary query options from the results page. Symantec Network Security provides query options as follows: ■ In Query Current Flows or Query Exported Flows ■ In Event Details, right-click the IP address to see the flow statistics ■ In Event Details of an Exported Related Flows, exported flows are displayed The Network Security console retrieves a limited number of records for each query, which prevents overloading memory, and displays the results in a table. If more results are available, click Next Results to proceed. Viewing current flows View Current Flows enables you to search against all of the collected flows by FlowChaser. These flows are stored in memory so they are not persistent. To query current flows 1 In the Network Security console, click Flow > View Current Flows.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134

117
Reports and Queries
About querying flows
About querying flows
FlowChaser serves as a data source in coordination with Symantec Network
Security TrackBack, a response mechanism that traces a DoS attack or network
flow back to its source. The FlowChaser database can be queried for flows by
port and arbitrary address. The Network Security console
displays both current
flow data and exported flow data, and provides secondary query options from
the results page.
Symantec Network Security
provides query options as follows:
In Query Current Flows or Query Exported Flows
In Event Details, right-click the IP address to see the flow statistics
In Event Details of an Exported Related Flows, exported flows are displayed
The Network Security console retrieves a limited number of records for each
query, which prevents overloading memory, and displays the results in a table.
If more results are available, click Next Results to proceed.
Viewing current flows
View Current Flows enables you to search against all of the collected flows by
FlowChaser. These flows are stored in memory so they are not persistent.
To query current flows
1
In the Network Security console, click
Flow
>
View Current Flows
.
Flows by source port
This report lists the source ports of flows found on
devices with Flow Status Collection sensor mode enabled.
You can generate this report from within the Devices with
Flow Statistics report.
Flows by destination port
This report lists the destination ports of flows found on
devices with Flow Status Collection sensor mode enabled.
You can generate this report from within the Devices with
Flow Statistics report.
Flows by protocol
This report lists the protocols of flows found on devices
with Flow Status Collection sensor mode enabled. You
can generate this report from within the Devices with
Flow Statistics report.
Table 9-6
Drill-down-only reports
Report
Description