Chapter 5. REPORTING AND FOLLOW-UP ANALYSIS

image with no caption

The ability to view exactly what traffic passed over your network is a powerful tool, but what can anyone do with this data in its entirety? After all, very few people can eyeball a list of 15,000 flows and identify the 10 most active hosts, identify the most commonly used ports, or even rank them by IP. Carefully choosing flow files to examine and then filtering their contents can reduce the number of flows you have to read, but this still leaves you with a huge data set to integrate, aggregate, and analyze even on a small network. You need a tool to aggregate flow data, sort it, and display the cumulative ...

Get Network Flow Analysis now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.