Introduction
Real-time NetFlow Analyzer provides a granular view of your network traffic. Using this
tool you can see the last 5 to 60 minutes of flow data broken out by
applications, conversation, domains, endpoints, and protocols. You can use
Real-time NetFlow Analyzer to explore exactly how your bandwidth is being used and
by whom.
Capturing NetFlow Data
Before you can begin analyzing data exported by your NetFlow enabled
routers and switches, you need to capture the flows. Ensure you complete
the following tasks before attempting to monitor data with Real-time NetFlow Analyzer:
- Modify the configuration of your NetFlow device to ensure it is exporting
NetFlow data. Due to the large number of different routers and switches
that can export NetFlow data, consult your Cisco device documentation
as to how to enable NetFlow data export. A technical reference is
available on the SolarWinds website that provides guidance. For more
information, see
www.solarwinds.com/support/documentation.aspx and
review the Enabling NetFlow and NetFlow Data Export on Cisco Catalyst
Switches technical reference.
- Ensure you know the port on which to listen for NetFlow data. This port is
part of the configuration of the NetFlow device.
- Ensure you know the IP address or hostname of the NetFlow device.
- Ensure you know the community string or SNMP version 3 credentials.
To begin capturing your NetFlow data:
- Click Start > All Programs > SolarWinds Real-time NetFlow Analyzer > Real-time NetFlow Analyzer.
- Specify the port on which your NetFlow device is exporting data in the
Listen on port field.
-
Click Tools > Add NetFlow Device, and then specify the following
information on the NetFlow Device Credentials window.
- IP address or hostname of the NetFlow device
- Community string or SNMP version 3 credentials.
- Click Test, and then review the Credentials Test window.
- Make any necessary adjustments to your values on the NetFlow Device
Credentials window, and then click OK.
Note: If Real-time NetFlow Analyzer is able to see NetFlow data, a green check
mark is displayed in the Sending NetFlow column of the Realtime NetFlow
Analyzer user interface.
Storing NetFlow Data
Real-time NetFlow Analyzer stores up to 60 minutes of captured NetFlow data in
Microsoft Access-readable capture files. You can modify the location of
capture files by changing the path displayed in the Capture file field of the
Real-time NetFlow Analyzer user interface.
Analyzing NetFlow Data
Real-time NetFlow Analyzer offers up to 60 minutes of traffic to analyze, grouped in a
number of different ways:
- Applications
- Allows you to see all the traffic passing through the specific based on the
application. Applications use specific ports to send data. This mapping
between port, application, and traffic is used to create the specific data
points. Depending on the Top XX value, the number of applications listed
in the tree changes. Clicking the top node, Applications, provides an
inclusive graph.
- Conversations
- Allows you to see traffic based on source and destination IP, source and
destination port, and the protocol used. These 5 data points grouped
together and matched create a single conversation. For example, a
conversation between 1.1.10.10 and google.com is defined by 1.1.10.10,
google.com, port 80 (HTTP) on both IP addresses, and the TCP
protocol. Clicking an IP address in the tree provides a view of all the
other IP addresses or domains with which this IP address is
communication. Clicking the top node, Conversations, provides an
inclusive graph of your highest traffic conversations.
- Domains
- Allows you to see all traffic in a domain. The domain consists of all IP
addresses that were resolvable, using reverse DNS, to that domain.
Clicking a domain or IP address in the tree provides a view of all the
other domains or IP addresses with which this domain is communication.
Clicking the top node, Domains, provides an inclusive graph of all the
domains on which traffic is being detected.
- Endpoints
- Allows you to select specific IP addresses (hosts) and view all the data
transmitted and received by that host. Clicking the top node, Endpoints,
provides an inclusive graph. This view does not separate data by
application (port) or protocol, but provides an overview of your highest
traffic producers.
- Protocols
- Allows you to see all the traffic that matches a specific protocol, for
example, TCP or UDP. Clicking a specific protocol provides a view of the
individual applications the protocol to traverse the specified interface.
Clicking the top node, Protocols, provides an inclusive graph of all traffic
produced split into protocols.
To view the data collected in easily analyzed graphs:
- Click the interface through which NetFlow data is flowing and you want to
analyze, and then click Start Flow Capture.
- Review the information displayed in the analysis graphs.
Notes:
- The tree view can be expanded to reveal individual applications,
conversations, domains, endpoints, and protocols. The tree views
are dynamic and change based on time period and the selected Top
## number.
- The refresh rate is in seconds.
Defining Applications and Modifying Port Definitions
Real-time NetFlow Analyzer uses the port utilized by an application to define the application.
To modify the definition of a port or define an unknown port:
- Click the interface through which NetFlow data is flowing and you want to
analyze, and then click Start Flow Capture.
- Click Tools > Application Mappings.
- To add a new Application definition:
- Click the Add New Mapping (
) icon.
- Provide the appropriate information on the Add New Mapping window, and then click OK.
- Ensure the spreadsheet of applications, protocols, and ports is correct, and then click OK.
- To edit the definition of a port or Application:
- Click the Edit Selected Entry (
) icon.
- Modify the appropriate fields on the Edit Mapping window, and then click OK.
- Ensure the spreadsheet of applications, protocols, and ports is
correct, and then click OK.
Legal
Copyright 1995-2008 SolarWinds, Inc. All rights reserved worldwide. No part of this document may be reproduced by any means nor modified, decompiled, disassembled, published or distributed, in whole or in part, or translated to any electronic medium or other means without the written consent of SolarWinds. All right, title and interest in and to the software and documentation are and shall remain the exclusive property of SolarWinds and its licensors. SolarWinds Orion™, SolarWinds Exchange Monitor™, and SolarWinds Toolset™ are trademarks of SolarWinds. SolarWinds® and the SolarWinds logo are registered trademarks of SolarWinds. Microsoft Exchange Server, Windows Server, Windows Vista, and Windows XP are registered trademarks or trademarks of Microsoft Corporation in the United States and other countries. All other trademarks contained in this document and in the Software are the property of their respective owners.
SOLARWINDS DISCLAIMS ALL WARRANTIES, CONDITIONS OR OTHER TERMS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, ON SOFTWARE AND DOCUMENTATION FURNISHED HEREUNDER INCLUDING WITHOUT LIMITATION THE WARRANTIES OF DESIGN, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL SOLARWINDS, ITS SUPPLIERS OR ITS LICENSORS BE LIABLE FOR ANY DAMAGES, WHETHER ARISING IN TORT, CONTRACT OR ANY OTHER LEGAL THEORY EVEN IF SOLARWINDS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.