Skip to main content
Version: 2.10.2

Dashboards

App Navigation

The App dashboards are organized into logical groups, and could be accessed from the top navigation bar and drop-down menus.

Overview > Traffic Overview

Overview is the default dashboard showing high level traffic statistics, such as top talkers, top listeners, traffic by protocol, traffic by protocol and destination ports, and top devices and interfaces by traffic volume.

Overview > Traffic Overview TS

This is an alternative Overview dashboard built using Splunk tstats command. Tstats requires some fields to be placed in Splunk index at ingestion time, so make sure you have upgraded Technology Add-on for NetFlow (TA-netflow) to version 4.2.4 or later.

Set this dashboard as your default dashboard in case you ingest large volume of NetFlow data for better performance. Go to Splunk Settings > User interface > Navigation menus, select default and change it from:

<nav>
<collection label="Overview">
<view name="overview" default="true"/>
<view name="overview_ts"/>
<view name="overview_si"/>

to:

<nav>
<collection label="Overview">
<view name="overview"/>
<view name="overview_ts" default="true"/>
<view name="overview_si"/>
note

Note: "Open in search" on tstats (TS) dashboards opens the underlying | tstats query, and viewing raw Events from this search is not available.

Overview > Traffic Overview Metrics

This is alternative Overview dashboard in case you ingest NFO output into Splunk Metrics index.

Use this and other Metrics dashboards if you have large volumes of data or running searches for a long time range.

note

Note: "Open in search" in Metrics dashboards opens the underlying | mstats query, and viewing raw Events from this search is not available

Overview > Traffic Overview SI

This is yet another alternative Overview dashboard built using Splunk summary indexing.

For more information, see Summary Index for Large Volumes of Data.

Use this and other SI dashboards if you have extremely large volumes of data or running searches for a long time range.

Network Conversations

Network Conversations group has dashboards to view traffic statistics reported by the NFO Module Network Conversations. This group includes the following dashboards:

  1. Network Conversations by Traffic
  2. Network Conversations by Protocol and Port
  3. Network Conversations Cyber Threats
  4. Network Conversations Top Applications
  5. Network Conversations Top Users
  6. Network Conversations Top Applications and Users
  7. Network Conversations Accepts-Rejects
  8. Network Conversations Devices by Concurrent Connections
  9. Network Conversations by Duration
  10. Network Conversations by Country
  11. Network Conversations by Autonomous Systems

To learn more about this Module, see Network Conversations Monitor in NFO User Guide.

Hosts

Hosts group has dashboards to view traffic statistics from communicating peers point of view. For example, Traffic by Source IP dashboard shows top talkers, and the ability to drill down to communicating peers as well as seeing network devices that reported these network conversations. This group includes the following dashboards:

  1. Traffic by Source IP
  2. Traffic by Source IP with TCP Duration
  3. Traffic by Destination IP
  4. Traffic by Protocol and Port
  5. Traffic by Host Pairs
  6. Traffic by Protocol
  7. Traffic by Subnets
  8. Connection Details

Interfaces

Interfaces group has dashboards to view traffic statistics starting from network devices and interfaces. These dashboards allow you to drill down and see network conversations traversing network devices and interfaces. This group includes the following dashboards:

  1. Top Devices by Traffic
  2. Top Devices by Packet Rate
  3. Interfaces Utilization
  4. Interfaces Utilization with Traffic by ports, source/destination, CBQOS
  5. Watched Interfaces Utilization
  6. Interface Groups

Applications

Applications group has dashboards to view traffic statistics and usage of various applications and services. This group includes the following dashboards:

  1. Traffic by Protocol and Port
  2. Service Response Time
  3. Palo Alto Networks Top Applications
  4. Palo Alto Networks Top Applications and Users
  5. Cisco AVC Top Applications
  6. Cisco AVC Top Applications and Users

Cloud

Cloud group has dashboards to view traffic reported by your public cloud such as Amazon AWS, Microsoft Azure, and Google GPC. This group includes the following dashboards:

Amazon AWS

  1. AWS Traffic Overview
  2. AWS Traffic Overview Accepts-Rejects
  3. AWS Traffic by Source EC2 Instance
  4. AWS Traffic by Destination EC2 Instance
  5. AWS Traffic by Protocol and Port
  6. AWS Traffic by Protocol
  7. AWS Traffic by VPC
  8. AWS Traffic by Region
  9. AWS Traffic by Service
  10. AWS Visitors by Country
  11. AWS ENI Utilization

Microsoft Azure

  1. Azure Traffic Overview
  2. Azure Traffic Overview Accepts-Rejects
  3. Azure Inbound Traffic
  4. Azure Outbound Traffic
  5. Azure Traffic by Protocol and Port
  6. Azure Traffic by Protocol
  7. Azure Traffic by Virtual Network
  8. Azure Traffic by Region
  9. Azure Visitors by Country

Google Cloud

  1. GCP Traffic Overview
  2. GCP Traffic by Source VM
  3. GCP Traffic by Destination VM
  4. GCP Traffic by Protocol and Port
  5. GCP Traffic by Protocol
  6. GCP Traffic by VPC
  7. GCP Traffic by Zone
  8. GCP Visitors by Country

Security

Security group has dashboards to view malicious and unexpected traffic, as well as denied traffic reported by firewalls. This group includes the following dashboards:

  1. Cyber Threat Statistics
  2. DNS Security
  3. Cisco ASA Top Violators
  4. Palo Alto Networks Top Violators
  5. NSX Distributed Firewall Top Violators
  6. Assets Access Monitor
  7. Traffic Using Critical Ports
  8. Communications with Malicious Hosts

Firewalls

Firewalls group has dashboards to view traffic reported by your firewalls:

  1. Cisco ASA
  2. Palo Alto Networks
  3. VMware NSX Distributed Firewall

More Traffic Statistics

This group has various dashboards that don't belong to any groups mentioned above. They are:

  1. Top Talkers and Destinations with City Geolocations
  2. TCP Health
  3. Visitors by Country
  4. Traffic by Autonomous Systems
  5. Network Traffic by CBQoS
  6. Microsegmentation Analyzer and Planning
  7. Traffic Analyzer and Planning (based on my-subnets.csv lookup)
  8. Traffic by Subnet Groups
  9. Traffic by Subnet Groups SI

SNMP

These dashboards visualize SNMP polling feature of NetFlow Optimizer. They include:

  1. SNMP Polling
  2. SNMP Traps
  3. Interface Errors and Discards
  4. SNMP Devices CPU and Memory

NetFlow Recorder

These dashboards enable you to look back in time: search through network traffic captured in NFO and sent to Splunk when NFO "Replay" is pressed.

Searches, Reports, and Alerts

This group contains dashboards to search through raw events during investigations, run online and scheduled reports, and configure alerts.

Metrics / Tstats

This group contains alternative dashboards based on Splunk tstats command, metrics index, and summary indexes. Use these dashboards for better performance when you ingest large volumes of NetFlow data into Splunk.

For more information, visit Summary Index for Large Volumes of Data.

Configuration

This group contains configuration dashboards and Splunk index usage statistics by NFO instances, by network devices, by NFO Modules.

Dashboard Overview

Every dashboard has different filters at the top of the screen to enable further narrowing of the report. For example, the Traffic by Protocol and Port dashboard can be filtered by the NFO hostname, device group, device, source IP/mask, source port, destination IP/mask, destination port, protocol Advanced Filter and time range.

Please note that source and destination IP/mask filters could be specified as subnets (IP/mask), as full IP addresses (199.45.1.45), or as a partial IP address (199.45.1.*).

In Advanced Filter you can specify any SPL to be appended to your search criteria, for example

src_ip!=10.* and dest_ip=192.*

Starting with release 3.7.81 the timeline panel enables you to “pan and zoom” into specific time period. The selected time interval is propagated into all drilldown panels as shown below.