You can setup alarms to trigger if traffic goes over defined threshold. Alarms can trigger:

  • on any node type (Exporter, Interface, Traffic Pattern, Subnet, Subnet Set, End Users)
  • several traffic types (total, host, conversation...)
  • for bps, pps, fps traffic or its combination
  • for different direction of traffic (total, in, out, src in...)

Alarms can be sent to certain users to speed up notification of the right person.

On this page:

Viewing Alarms in NetFlow module

Alarms that occurred during Time Window specified are visible as indicators in the Flow Module within the Top talker table. For example, we can see below alarms for Facebook Traffic by hosts.

 

NetVizura NetFlow Analyzer - Alarm Indicator

 

Alarms that have an arrow to the right are active alarms (trigger condition is still active). Only alarm of the highest severity will be showed. The number in the Alarm table indicates how many alarms occurred for that table entry during the Time Window.

 

 

 

 

 

Click on the alarm indicator will take you to more detailed view of the alarm in the Alarm module.

Viewing All Alarms (Alarm Module)

To view all alarms, go to Alarm Module.

 

NetVizura NetFlow Alarm Module

 

Here you can see the list off all alarms that occurred within the selected Time Window. In our case, we see that there are several hosts with high FB traffic. Occurrence indicators visualize time when alarm started and ended. If the occurrence indicator blinks it means that the alarm did not end yet (it is still active).

You are also able to filter, sort, group alarms by source and view only active alarms according to your need.

 

 

 

Click on the Source link will take you to statistics for the defined scope and object for this alarm. In case of NetFlow alarm, it will jump to NetFlow module and show the corresponding node and traffic chart.

Creating NetFlow Alarms

Error rendering macro 'excerpt-include'

No link could be created for 'Configuring NetFlow Alarms'.

 

  • No labels