Most Active Hosts for Palo Alto Networks (10033 / 20033)
This Module utilizes Palo Alto Networks NetFlow v9 reporting and provides a list of most active hosts by the number of initiated connections. Most active hosts are reported by Network Device and by Destination Port over a time interval. The number of reported top most active hosts (N) and the observation interval (T, sec) are configurable. This information is provided per NetFlow exporter.
Data Collection Interval, sec
Module logic execution interval
min = 10 sec, max = 600 sec, default = 30 sec
Application protocol (l4_dst_port) list
List of watched layer 4 destination ports. If specified, the traffic is reported by specified ports, and all other traffic is summed up under dest_port=0. If the list is empty, the traffic is reported by all actual destination ports.
e.g. 80, 443
N – number of reported hosts
Top N (number of reported destinations)
min = 0, max = 100000, default = 50 (0 indicates all hosts are reported)
Enable(1) or disable (0) reporting by destination port
If set to 1, enable network traffic monitoring by destination port. If set to 0, report total network traffic as destination port 0 (dest_port=0)