Skip to main content
Version: 2.3

Data streams

In the [Dashboard>Raw Data] menu there is a table with a list of all triggered alerts.

The data streams available in the system with default fields and user created fields are located in the [Dashboard>Raw Data] menu.

Introduction

At the top of the window you can find the standard search bar, time ranges menu, etc., these elements are described in User Interface . This view displays the netflow stream by default. To change it to another one, you need to do it in the searchbar.

image-20230705095859385

Above the table there is a graph in which the number of records recorded in the system in a unit of time is shown in bars on the timeline. In the table, the individual rows show the fields available for a given record in the selected data stream.

image-20230705095247961

info

In the table, for better readability of the data, the number of records displayed was limited to 1000.

Selecting which columns are displayed in the table is configured in the drop-down menu.

image-20230706093915267

In the System, the data streams are stored for a certain period of time, which is configured in the Retention menu. For performance and resource reasons, the netflow stream is usually kept as short as possible. You can see the range of available data in the chart by selecting a time period longer than the one configured in Retention for a given data stream. In this case, netflow is stored for up to 3 hours.

image-20230706103925486

Setting the time range to Last 12 hours you will see the records available in blue, the gray color presents the number of records that were available in the netflow stream while now this information is stored in the aggregated stream.

For aggregated streams, you have the ability to select the time resolution (auto/1 minute/10 minutes/1 hour/1 day) and you can select data due to traffic from the client or from the server (both/client/server).

image-20230706111224833

image-20230706111459110


Advanced View

After selecting a particular row by clicking on the row, a menu with Advanced View will open. All the variables, fields and values associated with the given record are available here.

image-20230706094203389

image-20230706094301239

When you select more rows in the table, the corresponding tabs will appear in the Advanced View menu.

image-20230706094507196


Right Click Menu

After right-clicking on a row, a Right Click menu with the following options will be shown:

image-20230705094519836

  • Action
    • Add value to lookup - adds the value to a lookup
  • Rest Client - sends an alert to another system using the REST CLIENT functionality
  • Resolve
    • RIPE - searches in the RIPE database
    • DNS for all values - resolves DNS for all IP addresses in the table
    • DNS - resolves DNS for the selected IP address
    • Ns lookup - queries a DNS Domain Name Server to the lookup to find DNS Records and IP address information
  • Net mask Search - access to quick IP network mask filter
  • Tools
    • Ping - simple PING tool
  • Mitigation
    • Block host by IP - address blocking when the system is integrated with the MACMON probe
  • Custom - you can create Your own Right Click action configured in the [Configuration>Objects>Right Click Actions] menu

Settings menu

The settings menu is accessed by pressing the image-20230630130509063 icon.

image-20230630132659466

The following actions are available here:

  • Server sorting switch

    • off - sorting is performed on records previously retrieved by the browser from the database (limited to 1000 records)
    • on - sorting is performed on the database and then retrieved by the browser (limited to 1000 records)
  • Export as

    • CSV - export alerts to CSV files which are displayed in the table (limited to 1000 records)
    • PDF - export alerts to PDF files which are displayed in the table (limited to 1000 records)
    • PNG - export alerts to PNG files which are displayed in the table (limited to 1000 records)
    • Full CSV Export - export all alerts that are in the System (database)

System Data streams

The Data streams implemented in the system along with the available fields are listed and described below.

netflow

Deduplicated Netflow and Sflow records stream.

Field NameNQL FieldDescription
TIMESTAMPTimeTime
CLIENT_IPClient IPClient IP Address
SERVER_IPServer IPServer IP Address
PROTOCOLProtocolProtocol Number
CLIENT_PORTClient PortClient Port
SERVER_PORTServer PortServer Port
APPLICATIONApplicationApplication Number
UNIQUE_SRC_EXP_IPSExporter IPsUnique IP Addresses of Netflow Exporters
UNIQUE_INTERFACESInterfacesUnique numbers of Netflow Exporters' Interfaces
CLIENT_FUNCTIONClient FunctionFunction Group of Client IP Addresses
SERVER_FUNCTIONServer FunctionFunction Group of Server IP Addresses
CLIENT_LOCATIONClient LocationLocation Group of Client IP Addresses
SERVER_LOCATIONServer LocationLocation Group of Server IP Addresses
CLIENT_ROLEClient RoleRole Group of Client IP Addresses
SERVER_ROLEServer RoleRole Group of Server IP Addresses
CLIENT_TCP_FLAGSClient TCP FlagsTCP Flags (Client -> Sever)
SERVER_TCP_FLAGSServer TCP FlagsTCP Flags (Sever -> Client)
UNIQUE_TOS_VALUESToS NumbersUnique Type of Service values
UNIQUE_MPLS_LABELSMPLS LabelsUnique MPLS Labels
UNIQUE_ASN_NUMBERSAS NumbersUnique Autonomous Systems Numbers
ICMP_TYPEICMP TypeICMP Type
CLIENT_IP_COUNTRYClient CountryCountry of Client IP Addresses
SERVER_IP_COUNTRYServer CountryCountry of Server IP Addresses
CLIENT_IP_AS_NUMBERClient AS NumberAS Number of Client IP Addresses
SERVER_IP_AS_NUMBERServer AS NumberAS Number of Server IP Addresses
ACTIVE_TIMEActive TimeActive Time of unique flow (session)
FIRST_TIMESTAMPFirst TimestampFirst Timestamp of unique flow (session)
LAST_TIMESTAMPLast TimestampLast Timestamp of unique flow (session)
CLIENT_BYTESClient BytesBytes (Client -> Sever)
SERVER_BYTESServer BytesBytes (Sever -> Client)
CLIENT_PACKETSClient PacketsPackets (Client > Sever)
SERVER_PACKETSServer PacketsPackets (Sever -> Client)
CLIENT_BITS_PER_SECClient Bits/sBits per Active Time (Client -> Sever)
SERVER_BITS_PER_SECServer Bits/sBits per Active Time (Sever -> Client)
CLIENT_PACKETS_PER_SECClient Packets/sPackets per Active Time (Client -> Sever)
SERVER_PACKETS_PER_SECServer Packets/sPackets per Active Time (Sever -> Client)
CLIENT_BITS_PER_PACKETAvg Client Bits/pktAvg Bits per Packet (Client -> Sever)
SERVER_BITS_PER_PACKETAvg Server Bits/pktAvg Bits per Packet (Sever -> Client)
AVG_CLIENT_BITS_PER_SECAvg Client Bits/sAvg Bits per Interval (Client -> Sever)
AVG_SERVER_BITS_PER_SECAvg Server Bits/sAvg Bits per Interval (Sever -> Client)
AVG_CLIENT_PACKETS_PER_SECAvg Client Packets/sAvg Packets per Interval (Client -> Sever)
AVG_SERVER_PACKETS_PER_SECAvg Server Packets/sAvg Packets per Interval (Sever -> Client)
CLIENT_MIN_IP_LENGTHClient Min Packet LengthMin Packet Length (Client -> Sever)
CLIENT_MAX_IP_LENGTHClient Max Packet LengthMax Packet Length (Client -> Sever)
RETRANSMITTED_IN_BYTESRetransmitted In BytesRetransmitted Bytes (Incoming)
RETRANSMITTED_OUT_BYTESRetransmitted Out BytesRetransmitted Bytes (Outgoing)
RETRANSMITTED_IN_PKTSRetransmitted In PacketsRetransmitted Packets (Incoming)
RETRANSMITTED_OUT_PKTSRetransmitted Out PacketsRetransmitted Packets (Outgoing)
CLIENT_MAX_TTLClient Max TTLMax TTL (Client -> Sever)
CLIENT_NW_LATENCY_MSClient Network TimeNetwork Latency (Client -> Server)
SERVER_NW_LATENCY_MSServer Network TimeNetwork Latency (Server -> Client)
APPL_LATENCY_MSInitial Server Response TimeResponse Time (Latency) (Application)
IN_INTERFACEIn InterfaceInterface (Incoming)
OUT_INTERFACEOut InterfaceInterface (Outgoing)
FIREWALL_EVENTFirewall EventFirewall Event (ASA)
FW_EXT_EVENTFirewall Ext EventFirewall Extended Event (ASA)
MPLS_TOP_LABEL_EXPMPLS Top LabelMPLS Top Label
MPLS_LABEL_1MPLS Label 1MPLS Label 1
MPLS_LABEL_2MPLS Label 2MPLS Label 2
MPLS_LABEL_3MPLS Label 3MPLS Label 3
MPLS_LABEL_4MPLS Label 4MPLS Label 4
MPLS_LABEL_5MPLS Label 5MPLS Label 5
SRC_ASSource ASSource Autonomous Systems
DST_ASDestination ASDestination Autonomous Systems
NF_F_XLATE_SRC_ADDR_IPV4Post Nat Source IPPost Nat Source IP Address
NF_F_XLATE_SRC_PORTPost Nat Source PortPost Nat Source Port
MIN_IP_LENGTHMin Packet LengthMin Packet Length
MAX_IP_LENGTHMax Packet LengthMax Packet Length
FLOW_LABELFlow LabelFlow Label
IPV6_OPTION_HEADERSIpv6 OptionsIPv6 Options
SRC_VLANSource VLANSource VLAN
DST_VLANDestination VLANDestination VLAN
IP_TOSToSType of Service number
FORWARDING_STATUSForwarding StatusForwarding Status
RETRANSMITTED_IN_BYTESRetransmitted In BytesRetransmitted Bytes (Incoming)
RETRANSMITTED_OUT_BYTESRetransmitted Out BytesRetransmitted Bytes (Outgoing)
RETRANSMITTED_IN_PKTSRetransmitted In PacketsRetransmitted Packets (Incoming)
RETRANSMITTED_OUT_PKTSRetransmitted Out PacketsRetransmitted Packets (Outgoing)
CLIENT_MAX_TTLClient Max TTLMax TTL (Client -> Sever)
CLIENT_NW_LATENCY_MSClient Network TimeNetwork Latency (Client -> Server)
SERVER_NW_LATENCY_MSServer Network TimeNetwork Latency (Server -> Client)
APPLICATION_IDApplication IDApplication ID
APPL_LATENCY_MSInitial Server Response TimeInitial Server Response Time

netflowTotalAggr

Field NameNQL FieldDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Bits/savgBitsPerSecondAvg Bits per Interval
Avg Packets/savgPacketsPerSecondAvg Packets per Interval
Bits/sbitsPerSecondBits per Active Time

netflowByIfcAggr

Netflow 1 min aggregated by interface flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Exporter IPexporterIpExporter IP
Exporter NameexporterNameLookup - Exporter IP as Exporter Name from SNMP database
Interface IndexifcIndexInterface Index
Interface NameifcNameLookup - Interface Index as Interface Name from SNMP database
FlowsflowsFlows sent by Exporter
In BytesinBytesBytes (In)
Out BytesoutBytesBytes (Out)
In PacketsinPacketsPackets (In)
Out PacketsoutPacketsPackets (Out)
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
In BitsinBitsBits (In)
Out BitsoutBitsBits (Out)
Avg Flows/savgFlowsPerSecondAvg Flows per Interval
Avg In Packets/savgInPacketsPerSecondAvg Packets (In) per Interval
Avg Out Packets/savgOutPacketsPerSecondAvg Packets (Out) per Interval
Avg In Bits/savgInBitsPerSecondAvg Bits (In) per Interval
Avg Out Bits/savgOutBitsPerSecondAvg Bits (Out) per Interval
% In UtilizationpctInUtilization% Utilization (In)
% Out UtilizationpctOutUtilization% Utilization (Out)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval

netflowByAppAggr

Netflow 1 min aggregated by application flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
ApplicationapplicationApplication
Application NameapplicationNameApplication Name
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
Server Network TimeserverNetworkTimeNetwork Latency from Server Side
Initial Server Response TimeinitialServerResponseTimeInitial Server Response Time
Client Network TimeclientNetworkTimeNetwork Latency from Client Side
In Retransmitted PacketsretransmittedInPacketsRetransmitted Packets (Client -> Server)
Out Retransmitted PacketsretransmittedOutPacketsRetransmitted Packets (Server -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
% In Retransmitted PacketspercentRetransmittedInPacketsPercent of Retransmitted Packets (Client -> Server)
% Out Retransmitted PacketspercentRetransmittedOutPacketsPercent of Retransmitted Packets (Server -> Client)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time
Client TCP FlagsclientTcpFlagsMapper - TCP Flags (Client -> Sever)
Server TCP FlagsserverTcpFlagsMapper - TCP Flags (Sever -> Client)

netflowByAsnAggr

Netflow 1 min aggregated by ASN flows stream.

Field NameNQL FieldDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
AS NumberasNumberAS Number
AS NameasNameLookup - AS Number to AS Name from build-in database
DirectionasDirectionDirection
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByGroupAggr

Netflow 1 min aggregated by group flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Group NamegroupNameLocation Group Name
DirectiongroupDirectionDirection
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

Group Function

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Exporter IPexporterIpExporter IP
Exporter NameexporterNameLookup - Exporter IP as Exporter Name from SNMP database
Interface IndexifcIndexInterface Index
Interface NameifcNameLookup - Interface Index as Interface Name from SNMP database
FlowsflowsFlows sent by Exporter
In BytesinBytesBytes (In)
Out BytesoutBytesBytes (Out)
In PacketsinPacketsPackets (In)
Out PacketsoutPacketsPackets (Out)
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
In BitsinBitsBits (In)
Out BitsoutBitsBits (Out)
Avg Flows/savgFlowsPerSecondAvg Flows per Interval
Avg In Packets/savgInPacketsPerSecondAvg Packets (In) per Interval
Avg Out Packets/savgOutPacketsPerSecondAvg Packets (Out) per Interval
Avg In Bits/savgInBitsPerSecondAvg Bits (In) per Interval
Avg Out Bits/savgOutBitsPerSecondAvg Bits (Out) per Interval
% In UtilizationpctInUtilization% Utilization (In)
% Out UtilizationpctOutUtilization% Utilization (Out)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval

Group Role

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Group NamegroupNameRole Group Name
DirectiongroupDirectionDirection
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByCountryAggr

Netflow 1 min aggregated by country flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Country NamecountryNameCountry Name
Country CodecountryCodeCountry Code
DirectioncountryDirectionDirection
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByExporterAggr

Netflow 1 min aggregated by exporter flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Exporter IPexporterIpExporter IP
Exporter NameexporterNameLookup - Exporter IP as Exporter Name from SNMP database
Exporter DescriptionexporterDescriptionLookup - Exporter IP as Exporter Description from SNMP database
Exporter LocationexporterLocationlookup("snmp-int-exp", "dev.loc", {"exporterIp": exporterIp})
FlowsflowsFlows sent by Exporter
BytesbytesBytes
PacketspacketsPackets
BitsbitsBits
Avg Flows/savgFlowsPerSecondAvg Flows per Interval
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval

netflowByIpAggr

Netflow 1 min aggregated by top IP flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
IP AddressipAddressIP Address
IP Address NameipAddressNameIP Address Name
AS NameasNameLookup - AS Number to AS Name from build-in database
Country CodecountryCodeMapper - IP Address to Country Code from build-in database
DirectionipDirectionDirection
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
Server Network TimeserverNetworkTimeNetwork Latency from Server Side
Initial Server Response TimeinitialServerResponseTimeInitial Server Response Time
Client Network TimeclientNetworkTimeNetwork Latency from Client Side
In Retransmitted PacketsretransmittedInPacketsRetransmitted Packets (Client -> Server)
Out Retransmitted PacketsretransmittedOutPacketsRetransmitted Packets (Server -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Client Bits/pktavgClientBitsPerPacketAvg Bits per Packet (Client -> Sever)
Avg Server Bits/pktavgServerBitsPerPacketAvg Bits per Packet (Sever -> Client)
Avg Client Bits/flowavgClientBitsPerFlowAvg Bits per Flow (Client -> Sever)
Avg Server Bits/flowavgServerBitsPerFlowAvg Bits per Flow (Sever -> Client)
Avg Client Packets/flowavgClientPacketsPerFlowAvg Packets per Flow (Client -> Sever)
Avg Server Packets/flowavgServerPacketsPerFlowAvg Packets per Flow (Sever -> Client)
% In Retransmitted PacketspercentRetransmittedInPacketsPercent of Retransmitted Packets (Client -> Server)
% Out Retransmitted PacketspercentRetransmittedOutPacketsPercent of Retransmitted Packets (Server -> Client)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByMplsAggr

Netflow 1 min aggregated by MPLS flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
MPLS LabelmplsUnique MPLS Label
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByProtocolAggr

Netflow 1 min aggregated by IP protocol flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Protocol NumberprotocolProtocol Number
Protocol NameprotocolNameProtocol Name
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByTosAggr

Netflow 1 min aggregated by TOS flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
ToS NumbertosNumberToS Number
ToS NametosNameToS Name
FlowsflowsFlows sent by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Active Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

alerts

Alerts stream.

Field NameNQL NameDescription
Alert IdidAlert Identifier
TimetimestampAlert Time
Rule TypealertRuleTypeRule Type
Alert NamealertNameAlert Name
Rule IdalertRuleIdRule Identifier
Alert DescriptionalertDescriptionAlert Description
Alert SeverityalertSeverityAlert Severity
Threshold LevelalertThresholdLevelThreshold Level (Critical, Major, Minor)
Alert TagsalertTagsTags
Mitre TacticalertMitreTacticMitre ATT&CK Tactic
Mitre TechniquealertMitreTechniqueMitre ATT&CK Technique Id
Mitre Technique IdalertMitreTechniqueIdMitre ATT&CK Technique Id
Mitre SubtechniquealertMitreSubtechniqueMitre ATT&CK Subtechnique
CorrelationsalertCorrelationsRule Correlations
Mitigation SystemalertMitigationSystemMitigation System
Mitigation IPalertMitigationIpFieldMitigation IP
Raw DatarawDataRaw Data
ACKalertAckSetting the Acknowledge flag
ACK UseralertAckUserUser updating the Acknowledge flag
ACK TimealertAckLastUpdateAcknowledge flag update Time
False PositivealertFalsePositiveAlert handling False Positive flag
FP UseralertFalsePositiveUserUser updating the False Positive flag
FP TimealertFalsePositiveLastUpdateFalse Positive flag update time
CommentalertCommentComment
Commented UseralertCommentUserUser updating a comment
Comment TimealertCommentLastUpdateComment update time
Client IPclientIpClient IP
Client PortclientPortClient Port
Client TCP FlagsclientTcpFlagsClient TCP Flags
Client GroupclientGroupsClient Group
Client CountryclientCountryClient Country
Client MacclientMacClient Mac
Client HostnameclientHostnameClient Hostname
Server IPserverIpServer IP
Server PortserverPortServer Port
Server TCP FlagsserverTcpFlagsServer TCP Flags
Server GroupserverGroupsServer Group
Server CountryserverCountryServer Country
Server MacserverMacServer Mac
Server HostnameserverHostnameServer Hostname
UsernameuserUsername
Unique Client IPsuniqueClientIPsUnique Client IPs
Unique Server IPsuniqueServerIPsUnique Server IPs
Unique Server PortsuniqueServerPortsUnique Server Ports
Unique Client ASNsuniqueClientASNsUnique Client ASNs
Unique Server ASNsuniqueServerASNsUnique Server ASNs
Unique Client CountriesuniqueClientCountriesUnique Client Countries
Unique Server CountriesuniqueServerCountriesUnique Server Countries
BPF_bpfBytes Per Flow
BPP_bppBytes Per Packet
Bytes_bytesSum Bytes
Flows_flowsSum Flows
Packets_packetsSum Packets
PPF_ppfPackets Per Flow
PPS_ppsPackets Per Second
SYN_synCount of SYN flags
Unique ASN_uniqueASNsUnique Count of ASNs
Unique ClientIPs_uniqueClientIPsUnique Count of Client IPs
Unique ServerIPs_uniqueServerIPsUnique Count of Server IPs
Unique Server Ports_uniqueServerPortUnique Count of Server Port