SlideShare a Scribd company logo
Free training on NetFlow Analyzer - Part II
Diagnosing and troubleshooting
traffic issues faster
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer Training
Agenda
‱ Customizing data storage
‱ Customizing dashboards
‱ Reporting and automation
‱ Troubleshooting with forensics
‱ Traffic shaping
‱ Capacity planning and billing
NetFlow Analyzer 123083
How long data is stored for
troubleshooting
Customizing storage settings
Aggregated dataRaw data
One-minute data
Aggregated data
Default ON
Raw data
Default OFF
Types of data storage
‱ Each and every detail on application, source,
destination, and more
‱ Storage time limit (one hour to one month)
‱ By default one day is selected
‱ Improve raw storage up to one year with High
Perf
‱ Troubleshoot faster with forensics
‱ Stores "top 100" records for
conversation by default (Up to 300
records)
‱ Retains data forever by default
‱ Historical reporting
Benefit of turning on raw data
‱ One-minute granularity for the most detailed traffic analysis
‱ Long-term storage for better root cause analysis
‱ Improves accuracy with each and every conversation detail
‱ Deeper insights for troubleshooting with forensics reports
‱ Real-time alerts to troubleshoot issues immediately
http://blogs.manageengine.com/product-blog/netflowanalyzer/2010/01/29/data-storage-pattern-in-netflow-analyzer.html
Other storage settings
One-minute traffic data
‱ Interface traffic graph for any 24-hour period
‱ Capacity planning traffic report
‱ Compare report
Raw data
‱ Forensics
‱ Last 2 hour for interface snapshot graphs
‱ Traffic details for App flow, Medianet, Multicast, AVC and ASA flow.
Aggregated data
‱ All widgets in inventory (Application, conversation and QoS)
‱ All interfaces and graphs, except a traffic graph for any 24-hour period
‱ Search and custom search report
‱ Consolidated report
‱ Schedule report
‱ Report profile
Data storage summary
How to identify potential issues early
Traffic summary dashboards
Top N applicationsDevice summary
Top N protocols Top N QoS
Top N conversations
View top N traffic details from the dashboard
‱ Track top N details in traffic summary
‱ Drill down to the most consumed traffic;
identify suspicious traffic
‱ Create new dashboards to view the
details that are important to you
‱ Display live data in your NOC screen
with auto-refresh option
Proactive alerting
Link congestionUtilization % exceeds
High traffic volume Link speed is low
Set alarms based on bandwidth usage
‱ Difference between
alarms and events
Alarms display:
‱ Message
‱ Source
‱ Category
‱ Technician
‱ Notes
‱ Severity
‱ Date/time
Possible options with alarms
‱ Drill down to faulty router/interface from
the alarm
‱ Note the exact time an issue occurred
‱ Check for traffic/application graphs
‱ Add notes to update the status of an
alarm
‱ Discuss issues with team members
An alarm is raised when WAN link utilization is more than 50%
How to find the root cause of an
issue
Easy reporting
CompareCustom search
Consolidated IP group and protocol
Forensics
Drill down to any specific detail with reports
Search/custom search report
Compare report
Consolidated report
IP group consolidated report
Protocol distribution report
Bandwidth analysis reports help you:
Search specific traffic details by the
associated application, protocol, host, or IP
Compare bandwidth usage at different
time intervals
Track top talkers and conversations with a
complete report
Visualize the combined bandwidth usage
of all IP groups
View protocol-based traffic for any
particular interface
Save all your reports in Report Profiles
Benefits of reporting
‱ Create criteria-based reports to identify bandwidth shortages or traffic spikes
‱ Automate and schedule reports at any specific time; receive notifications about reports
‱ Save reports and export them to PDF or CSV files to share them with upper management
‱ Generate historical reports to promptly diagnose bandwidth capacity
‱ Periodically review and optimize the usage of network bandwidth
Troubleshooting with forensics
What's the root cause of a traffic spike?
Benefits of forensics
‱ Get more granular traffic statistics using raw
data
‱ Drill down to identify which users,
applications, and protocols are consuming
the most bandwidth at a specific time
‱ Troubleshoot accurately by defining multiple
criteria to filter required traffic
‱ Flexibility to review historical data and find
out why a particular spike was generated
Real-life use case
There was major network congestion and
critical applications were running slowly...
WAN Congestion
...which affected all users connected to
the network. The biggest challenge was
figuring out how to quickly resolve the
issue.
Step 1: Determine which part of the network was experiencing congestion
Step 2: Identify what caused the congestion. App or user or external attack?
Step 3: Troubleshoot by applying policies and bring the network back up
Step 1: Determine which part of the network
was experiencing congestion
‱ Where is the congestion and is it notified to me?
‱ Which applications were contributing to the most traffic?
‱ What QoS precedence value was the traffic utilizing at the time?
‱ What were the top source, destination & conversations in the network?
The dashboard immediately provided
details on what was being affected.
Step 2: Use forensics to identify what
caused the congestion
‱ Which applications or users were consuming the most traffic?
‱ What was the top conversation in the network at that time?
Forensics help locate the real cause.
The issue was with a patch management upgrade that
happened on all windows server during business hours.
1. Block the IP using an access control list (ACL)
2. Reduce the traffic bandwidth utilization
3. Load share the traffic with the help of Compare Reports
4. Reschedule the action to occur during non-business hours
How to troubleshoot and fix the issue
1. Filter out excess router
traffic by blocking IP/ IP
network
2. Allow certain packets and
deny everything else
#1. Block the IP with an ACL
1. Tweak your traffic policies
with CBQoS configurations
2. Shape interface traffic and
prioritize your critical
applications
3. Monitor the policy change in
CBQoS graphs
#2. Reduce the bandwidth utilization
1. Compare multiple
devices across the same
time period to view each
one's capacity
2. Decide how much to
deviate traffic on each
interface/device
#3 and #4: Load share the traffic or
rescheduling using Compare Reports
Once the issue is resolved, generate a
consolidated report to view the traffic stats.
What should you do if your
bandwidth is slowly reaching its
limit?
Capacity planning
Know immediately when you've reached your maximum capacity.
Generate short-term or long-term reports to view your network's usage
trends.
Get meaningful insight into application growth, average usage, and any usage
deviations.
How to bill your customers correctly
Billing
Measure bandwidth usage to verify your ISP billing.
Generate bill plans for your customers/clients if you're an ISP.
How to optimize your current bandwidth?
2. Understand historic trends and shape non-business traffic.
3. Prioritize critical applications.
1. Segment the network by creating groups.
Bandwidth optimization techniques
iPhone app
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer Training
Summary
Need more help?
youtube.com/opmanagertechvideos
help.netflowanalyzer.com
forums.manageengine.com/netflowanalyzer
netflowanalyzer-support@manageengine.com
+1 (888) 720-9500 / +1 (408) 916 - 9595
Q&A
Thank you!
netflowanalyzer-support@manageengine.com

More Related Content

PDF
NETFLOW ANALYZER 9600 - AN OVERVIEW
PPTX
OpManager training - Device discovery and classification.
PPTX
Dashboards, widgets, business views & 3D-data centre
PPTX
Q4S protocol
PPTX
What's new in NetFlow Analyzer 12.2
PPTX
Webinar: How to troubleshoot bandwidth hogs and take action.
PPTX
Top 5 problems a NETWORK ANALYSIS TOOL will help you solve
PDF
Mobile QoS Management using Complex Event Processing
NETFLOW ANALYZER 9600 - AN OVERVIEW
OpManager training - Device discovery and classification.
Dashboards, widgets, business views & 3D-data centre
Q4S protocol
What's new in NetFlow Analyzer 12.2
Webinar: How to troubleshoot bandwidth hogs and take action.
Top 5 problems a NETWORK ANALYSIS TOOL will help you solve
Mobile QoS Management using Complex Event Processing

What's hot (20)

PPTX
5 ways you can benefit from OpManager Plus
PDF
Kentik Network@Scale (Dan Ellis)
PDF
Cloud-Scale BGP and NetFlow Analysis
PDF
Effective Service Mesh to turbocharge Cloud Resiliency
PPT
Chapter04
PDF
Cloud Aware Network Management
PPTX
Enterprise campus networks
PPTX
Network latency - measurement and improvement
PDF
Kentik Detect Engine - Network Field Day 2017
PDF
1. Network Security Monitoring Rationale
PPTX
Leading datacenter monitors 1500 interfaces using NetFlow Analyzer
PDF
Internet Measurement Network
PDF
Network Latency
PDF
Atlas Services Remote Analysis Report Sample
PDF
OpenMAMA Governance
PDF
Fracton tarec in offerings intro
PDF
CNIT 50: 9. NSM Operations
PDF
Monalytics - Online Monitoring and Analytics for Large Scale Data Centers
PDF
German Sviridov - PhD defense
PPTX
Beyond FTP & hard drives: Accelerating LAN file transfers
5 ways you can benefit from OpManager Plus
Kentik Network@Scale (Dan Ellis)
Cloud-Scale BGP and NetFlow Analysis
Effective Service Mesh to turbocharge Cloud Resiliency
Chapter04
Cloud Aware Network Management
Enterprise campus networks
Network latency - measurement and improvement
Kentik Detect Engine - Network Field Day 2017
1. Network Security Monitoring Rationale
Leading datacenter monitors 1500 interfaces using NetFlow Analyzer
Internet Measurement Network
Network Latency
Atlas Services Remote Analysis Report Sample
OpenMAMA Governance
Fracton tarec in offerings intro
CNIT 50: 9. NSM Operations
Monalytics - Online Monitoring and Analytics for Large Scale Data Centers
German Sviridov - PhD defense
Beyond FTP & hard drives: Accelerating LAN file transfers
Ad

Similar to Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer Training (20)

PPTX
Free Netflow analyzer training - diagnosing_and_troubleshooting
PPTX
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
PPTX
NetFlow Analyzer Training Part I: Getting the initial settings right
PPTX
How ManageEngine NetFlow Analyzer helped Boston Properties Save Bandwidth Costs
PPTX
Free NetFlow Analyzer training - Getting the initial settings right
PPTX
Network Bandwidth management - Mumbai Seminar
PPTX
Export flows, group traffic, map application traffic and more: NetFlow Analyz...
PPTX
The Need for Complex Analytics from Forwarding Pipelines
PPTX
Business Intelligent Reporting Process.pptx
 
PPTX
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
 
PPTX
Wikibon #IoT #HyperConvergence Presentation via @theCUBE
PPTX
Hyper-Convergence CrowdChat
PDF
Well_Monitoring_System_DataComm_Technology.pdf
PPTX
INT_Ch17.pptx
PDF
Orion NTA Customer Training
PDF
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
PPTX
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
 
PPT
NetFlow Auditor Anomaly Detection Plus Forensics February 2010 08
PPTX
Webinar: Five Problems Facing Business-Critical NFS Deployments
PPT
1. Network monitoring and measurement-2.ppt
Free Netflow analyzer training - diagnosing_and_troubleshooting
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part I: Getting the initial settings right
How ManageEngine NetFlow Analyzer helped Boston Properties Save Bandwidth Costs
Free NetFlow Analyzer training - Getting the initial settings right
Network Bandwidth management - Mumbai Seminar
Export flows, group traffic, map application traffic and more: NetFlow Analyz...
The Need for Complex Analytics from Forwarding Pipelines
Business Intelligent Reporting Process.pptx
 
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
 
Wikibon #IoT #HyperConvergence Presentation via @theCUBE
Hyper-Convergence CrowdChat
Well_Monitoring_System_DataComm_Technology.pdf
INT_Ch17.pptx
Orion NTA Customer Training
PLNOG15: Network Monitoring&Data Analytics at 10/40/100GE speeds. Why spend a...
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
 
NetFlow Auditor Anomaly Detection Plus Forensics February 2010 08
Webinar: Five Problems Facing Business-Critical NFS Deployments
1. Network monitoring and measurement-2.ppt
Ad

More from ManageEngine, Zoho Corporation (20)

PPTX
Create seamless customer experiences
PDF
From web interface to database: Monitor what matters
PDF
NetFlow Analyzer Free Training Series Part I - May 2020
PDF
Overcome real-time server and VM monitoring challenges
PPTX
Modernizing Cloud and Hyperconverged Infrastructure monitoring
PPTX
Deliver seamless digital experience
PDF
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
PPTX
From web interface to the database:Monitor all that matters
PDF
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
PDF
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
PDF
NetFlow Analyzer Product Overview
PPTX
Monitoring cloud applications and hyperconverged infrastructure
PPTX
Building the right website monitoring strategy
PPTX
Unlock the value of your big data infrastructure
PPTX
Key to optimal end user experience
PPTX
Monitoring cloud applications and containers
PPTX
implementing the right website monitoring strategy
PPTX
Big data and non relational database
PPTX
Visibility-from web application interface to the database
PPTX
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Create seamless customer experiences
From web interface to database: Monitor what matters
NetFlow Analyzer Free Training Series Part I - May 2020
Overcome real-time server and VM monitoring challenges
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Deliver seamless digital experience
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
From web interface to the database:Monitor all that matters
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Product Overview
Monitoring cloud applications and hyperconverged infrastructure
Building the right website monitoring strategy
Unlock the value of your big data infrastructure
Key to optimal end user experience
Monitoring cloud applications and containers
implementing the right website monitoring strategy
Big data and non relational database
Visibility-from web application interface to the database
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps

Recently uploaded (20)

PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PPTX
Essential Infomation Tech presentation.pptx
PDF
Digital Strategies for Manufacturing Companies
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
PPTX
Transform Your Business with a Software ERP System
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
Reimagine Home Health with the Power of Agentic AI​
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PPTX
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
PDF
AI in Product Development-omnex systems
PDF
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
PDF
How Creative Agencies Leverage Project Management Software.pdf
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Understanding Forklifts - TECH EHS Solution
PPTX
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
 
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Navsoft: AI-Powered Business Solutions & Custom Software Development
Essential Infomation Tech presentation.pptx
Digital Strategies for Manufacturing Companies
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Odoo POS Development Services by CandidRoot Solutions
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Transform Your Business with a Software ERP System
wealthsignaloriginal-com-DS-text-... (1).pdf
2025 Textile ERP Trends: SAP, Odoo & Oracle
Reimagine Home Health with the Power of Agentic AI​
Odoo Companies in India – Driving Business Transformation.pdf
Oracle E-Business Suite: A Comprehensive Guide for Modern Enterprises
AI in Product Development-omnex systems
EN-Survey-Report-SAP-LeanIX-EA-Insights-2025.pdf
How Creative Agencies Leverage Project Management Software.pdf
Softaken Excel to vCard Converter Software.pdf
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Understanding Forklifts - TECH EHS Solution
Lecture 3: Operating Systems Introduction to Computer Hardware Systems
 

Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer Training

  • 1. Free training on NetFlow Analyzer - Part II Diagnosing and troubleshooting traffic issues faster
  • 3. Agenda ‱ Customizing data storage ‱ Customizing dashboards ‱ Reporting and automation ‱ Troubleshooting with forensics ‱ Traffic shaping ‱ Capacity planning and billing
  • 5. How long data is stored for troubleshooting
  • 6. Customizing storage settings Aggregated dataRaw data One-minute data
  • 7. Aggregated data Default ON Raw data Default OFF Types of data storage ‱ Each and every detail on application, source, destination, and more ‱ Storage time limit (one hour to one month) ‱ By default one day is selected ‱ Improve raw storage up to one year with High Perf ‱ Troubleshoot faster with forensics ‱ Stores "top 100" records for conversation by default (Up to 300 records) ‱ Retains data forever by default ‱ Historical reporting
  • 8. Benefit of turning on raw data ‱ One-minute granularity for the most detailed traffic analysis ‱ Long-term storage for better root cause analysis ‱ Improves accuracy with each and every conversation detail ‱ Deeper insights for troubleshooting with forensics reports ‱ Real-time alerts to troubleshoot issues immediately http://blogs.manageengine.com/product-blog/netflowanalyzer/2010/01/29/data-storage-pattern-in-netflow-analyzer.html
  • 10. One-minute traffic data ‱ Interface traffic graph for any 24-hour period ‱ Capacity planning traffic report ‱ Compare report Raw data ‱ Forensics ‱ Last 2 hour for interface snapshot graphs ‱ Traffic details for App flow, Medianet, Multicast, AVC and ASA flow. Aggregated data ‱ All widgets in inventory (Application, conversation and QoS) ‱ All interfaces and graphs, except a traffic graph for any 24-hour period ‱ Search and custom search report ‱ Consolidated report ‱ Schedule report ‱ Report profile Data storage summary
  • 11. How to identify potential issues early
  • 12. Traffic summary dashboards Top N applicationsDevice summary Top N protocols Top N QoS Top N conversations
  • 13. View top N traffic details from the dashboard ‱ Track top N details in traffic summary ‱ Drill down to the most consumed traffic; identify suspicious traffic ‱ Create new dashboards to view the details that are important to you ‱ Display live data in your NOC screen with auto-refresh option
  • 14. Proactive alerting Link congestionUtilization % exceeds High traffic volume Link speed is low
  • 15. Set alarms based on bandwidth usage ‱ Difference between alarms and events Alarms display: ‱ Message ‱ Source ‱ Category ‱ Technician ‱ Notes ‱ Severity ‱ Date/time
  • 16. Possible options with alarms ‱ Drill down to faulty router/interface from the alarm ‱ Note the exact time an issue occurred ‱ Check for traffic/application graphs ‱ Add notes to update the status of an alarm ‱ Discuss issues with team members An alarm is raised when WAN link utilization is more than 50%
  • 17. How to find the root cause of an issue
  • 18. Easy reporting CompareCustom search Consolidated IP group and protocol Forensics
  • 19. Drill down to any specific detail with reports Search/custom search report Compare report Consolidated report IP group consolidated report Protocol distribution report Bandwidth analysis reports help you: Search specific traffic details by the associated application, protocol, host, or IP Compare bandwidth usage at different time intervals Track top talkers and conversations with a complete report Visualize the combined bandwidth usage of all IP groups View protocol-based traffic for any particular interface
  • 20. Save all your reports in Report Profiles
  • 21. Benefits of reporting ‱ Create criteria-based reports to identify bandwidth shortages or traffic spikes ‱ Automate and schedule reports at any specific time; receive notifications about reports ‱ Save reports and export them to PDF or CSV files to share them with upper management ‱ Generate historical reports to promptly diagnose bandwidth capacity ‱ Periodically review and optimize the usage of network bandwidth
  • 22. Troubleshooting with forensics What's the root cause of a traffic spike?
  • 23. Benefits of forensics ‱ Get more granular traffic statistics using raw data ‱ Drill down to identify which users, applications, and protocols are consuming the most bandwidth at a specific time ‱ Troubleshoot accurately by defining multiple criteria to filter required traffic ‱ Flexibility to review historical data and find out why a particular spike was generated
  • 25. There was major network congestion and critical applications were running slowly...
  • 27. ...which affected all users connected to the network. The biggest challenge was figuring out how to quickly resolve the issue. Step 1: Determine which part of the network was experiencing congestion Step 2: Identify what caused the congestion. App or user or external attack? Step 3: Troubleshoot by applying policies and bring the network back up
  • 28. Step 1: Determine which part of the network was experiencing congestion ‱ Where is the congestion and is it notified to me? ‱ Which applications were contributing to the most traffic? ‱ What QoS precedence value was the traffic utilizing at the time? ‱ What were the top source, destination & conversations in the network? The dashboard immediately provided details on what was being affected.
  • 29. Step 2: Use forensics to identify what caused the congestion ‱ Which applications or users were consuming the most traffic? ‱ What was the top conversation in the network at that time? Forensics help locate the real cause. The issue was with a patch management upgrade that happened on all windows server during business hours.
  • 30. 1. Block the IP using an access control list (ACL) 2. Reduce the traffic bandwidth utilization 3. Load share the traffic with the help of Compare Reports 4. Reschedule the action to occur during non-business hours How to troubleshoot and fix the issue
  • 31. 1. Filter out excess router traffic by blocking IP/ IP network 2. Allow certain packets and deny everything else #1. Block the IP with an ACL
  • 32. 1. Tweak your traffic policies with CBQoS configurations 2. Shape interface traffic and prioritize your critical applications 3. Monitor the policy change in CBQoS graphs #2. Reduce the bandwidth utilization
  • 33. 1. Compare multiple devices across the same time period to view each one's capacity 2. Decide how much to deviate traffic on each interface/device #3 and #4: Load share the traffic or rescheduling using Compare Reports
  • 34. Once the issue is resolved, generate a consolidated report to view the traffic stats.
  • 35. What should you do if your bandwidth is slowly reaching its limit?
  • 36. Capacity planning Know immediately when you've reached your maximum capacity. Generate short-term or long-term reports to view your network's usage trends. Get meaningful insight into application growth, average usage, and any usage deviations.
  • 37. How to bill your customers correctly
  • 38. Billing Measure bandwidth usage to verify your ISP billing. Generate bill plans for your customers/clients if you're an ISP.
  • 39. How to optimize your current bandwidth?
  • 40. 2. Understand historic trends and shape non-business traffic. 3. Prioritize critical applications. 1. Segment the network by creating groups. Bandwidth optimization techniques
  • 45. Q&A