SlideShare a Scribd company logo
Diagnosing and
troubleshooting
traffic issues faster
Free training on NetFlow Analyzer: Part II
Welcome to a free training on
NetFlow Analyzer!
Can you hear me?
Can you see the presentation?
Please confirm by commenting in the chat panel.
Trainer
Piyushree
NetFlow Analyzer product expert
Part II
Diagnosing and troubleshooting
traffic issues faster
Agenda
• Customizing data storage
• Customizing dashboards
• Reporting and automation
• Troubleshooting with forensics
• Traffic shaping
• Capacity planning and billing
Major concerns while troubleshooting
an issue
• How do I control how long data is stored for troubleshooting?
• How do I identify potential issues early and get alerted about them?
• How do I find the root cause of an issue?
• How do I troubleshoot and resolve an issue?
• How do I optimize traffic and check if my bandwidth is slowly reaching its limit?
• How do I know if I'm being overcharged by my ISP?
How long data is stored for
troubleshooting
Customizing storage settings
Aggregated dataRaw data
One-minute data
Aggregated data
Default ON
Raw data
Default OFF
Types of data storage
• Each and every detail on application, source,
destination, and more
• Storage time limit (one hour to one month)
• By default one day is selected
• Improve raw storage up to one year with
High Perf
• Troubleshoot faster with forensics
• Stores "top 100" records for
conversation by default (Up to 300
records)
• Retains data forever by default
• Capacity planning and long-term
reporting
Other storage settings
Benefit of turning on raw data
• One-minute granularity for the most detailed traffic analysis
• Long-term storage for better root cause analysis
• Improves accuracy with each and every conversation detail
• Deeper insights for troubleshooting with forensics reports
• Real-time alerts to troubleshoot issues immediately
http://blogs.manageengine.com/product-blog/netflowanalyzer/2010/01/29/data-storage-pattern-in-netflow-analyzer.html
Why you need a High Perf reporting engine
database
So you can:
1. Handle huge volumes of traffic with raw data
2. Improve accuracy of traffic analysis
3. Generate insightful reports faster
4. Increase your raw data storage period up to one year
5. Follow capacity trends and troubleshoot efficiently
One-minute traffic data
• Interface traffic graph for any 24-hour period
• Capacity planning traffic report
• Compare report
Raw data
• Forensics
• Last 2 hour for interface snapshot graphs
• Traffic details for App flow, Medianet, Multicast, AVC and ASA flow.
Aggregated data
• All widgets in inventory (Application, conversation and QoS)
• All interfaces and graphs, except a traffic graph for any 24-hour period
• Search and custom search report
• Consolidated report
• Schedule report
• Report profile
Data storage summary
How to identify potential issues early
Traffic summary dashboards
Top N applicationsDevice summary
Top N protocols Top N QoS
Top N conversations
View top N traffic details from the dashboard
• Track top N details in traffic summary
• Drill down to the most consumed
traffic; identify suspicious traffic
• Create new dashboards to view the
details that are important to you
• Display live data in your NOC screen
with auto-refresh option
Proactive alerting
Link congestionUtilization % exceeds
High traffic volume Link speed is low
Set alarms based on bandwidth usage
• Difference between
alarms and events
Alarms display:
• Message
• Source
• Category
• Technician
• Notes
• Severity
• Date/time
Possible options with alarms
• Drill down to faulty router/interface
from the alarm
• Note the exact time an issue occurred
• Check for traffic/application graphs
• Add notes to update the status of an
alarm
• Discuss issues with team members
An alarm is raised when WAN link utilization is more than 50%
How to find the root cause of an issue
Easy reporting
CompareCustom search
Consolidated IP group and protocol
Forensics
Drill down to any specific detail with reports
Search/custom search report
Compare report
Consolidated report
IP group consolidated report
Protocol distribution report
Bandwidth analysis reports help you:
Search specific traffic details by the
associated application, protocol, host, or IP
Compare bandwidth usage at different
time intervals
Track top talkers and conversations with
a complete report
Visualize the combined bandwidth usage
of all IP groups
View protocol-based traffic for any
particular interface
Save all your reports in Report Profiles
Benefits of reporting
• Create criteria-based reports to identify bandwidth shortages or traffic spikes
• Automate and schedule reports at any specific time; receive notifications about reports
• Save reports and export them to PDF or CSV files to share them with upper management
• Generate historical reports to promptly diagnose bandwidth capacity
• Periodically review and optimize the usage of network bandwidth
Troubleshooting with forensics
What's the root cause of a traffic spike?
Benefits of forensics
• Get more granular traffic statistics using
raw data
• Drill down to identify which users,
applications, and protocols are consuming
the most bandwidth at a specific time
• Troubleshoot accurately by defining
multiple criteria to filter required traffic
• Flexibility to review historical data and find
out why a particular spike was generated
Real-life use case
There was major network congestion and
critical applications were running slowly...
Free Netflow analyzer  training - diagnosing_and_troubleshooting
...which affected all users connected to the
network. The biggest challenge was
figuring out how to quickly resolve the
issue.
Step 1: Determine which part of the network was experiencing congestion
Step 2: Identify what caused the congestion. App or user or external attack?
Step 3: Troubleshoot by applying policies and bring the network back up
Step 1: Determine which part of the network
was experiencing congestion
• Where is the congestion and is it notified to me?
• Which applications were contributing to the most traffic?
• What QoS precedence value was the traffic utilizing at the time?
• What were the top source, destination & conversations in the network?
The dashboard immediately provided
details on what was being affected.
Step 2: Use forensics to identify what
caused the congestion
• Which applications or users were consuming the most traffic?
• What was the top conversation in the network at that time?
Forensics help locate the real cause.
The issue was with a patch management upgrade that
happened on all windows server during business hours.
1. Block the IP using an access control list (ACL)
2. Reduce the traffic bandwidth utilization
3. Load share the traffic with the help of Compare Reports
4. Reschedule the action to occur during non-business hours
How to troubleshoot and fix the issue
1. Filter out excess router
traffic by blocking IP/ IP
network
2. Allow certain packets
and deny everything
else
#1. Block the IP with an ACL
1. Tweak your traffic policies
with CBQoS configurations
2. Shape interface traffic and
prioritize your critical
applications
3. Monitor the policy change
in CBQoS graphs
#2. Reduce the traffic bandwidth utilization
1. Compare multiple
devices across the same
time period to view each
one's capacity
2. Decide how much to
deviate traffic on each
interface/device
#3 and #4: Load share the traffic or
rescheduling using Compare Reports
Once the issue is resolved, generate a
consolidated report to view the traffic stats.
What should you do if your bandwidth
is slowly reaching its limit?
Capacity planning
Know immediately when you've reached your maximum capacity.
Generate short-term or long-term reports to view your network's usage trends.
Get meaningful insight into application growth, average usage, and any usage deviations.
How to bill your customers correctly
Billing
Measure bandwidth usage to cross-check with your ISP billing.
Generate bill plans for your customers/clients if you're an ISP.
iPhone app
Free Netflow analyzer  training - diagnosing_and_troubleshooting
Summary
Need more help?
youtube.com/netflowanalyzertechvideos
help.netflowanalyzer.com
forums.manageengine.com/netflowanalyzer
netflowanalyzer-support@manageengine.com
+1 (888) 720-9500 / +1 (408) 916 - 9595
Q&A
Thank you!
Piyushree
piyushree.n@zohocorp.com

More Related Content

PPTX
Dashboards, widgets, business views & 3D-data centre
PPTX
Free NetFlow Analyzer training - Getting the initial settings right
PPTX
Network fault management and IT automation training
PPTX
OpManager training - Device discovery and classification.
PPTX
Leading American Entertainment Company implements OpManager
PPTX
World's Largest Space Research Organization Implements OpManager Plus
PPTX
5 reasons to use OpManager Plus
PPTX
Configlets, compliance, RBAC & reports - Network Configuration Manager
Dashboards, widgets, business views & 3D-data centre
Free NetFlow Analyzer training - Getting the initial settings right
Network fault management and IT automation training
OpManager training - Device discovery and classification.
Leading American Entertainment Company implements OpManager
World's Largest Space Research Organization Implements OpManager Plus
5 reasons to use OpManager Plus
Configlets, compliance, RBAC & reports - Network Configuration Manager

What's hot (20)

PPTX
5 ways you can strengthen and secure your network infrastructure with Firewal...
PPTX
5 Ways NCM Can Save You From A Disaster
PPTX
Network and server performance monitoring training
PPTX
Gulf Chemicals & Metallurgy manages 1700 interfaces with OpManager
PPTX
Top 5 IT challenges for 2017
PPTX
IT Solutions Provider in Kosovo uses Bandwidth monitoring, NetFlow Analyzer
PPTX
Top 5 problems a NETWORK ANALYSIS TOOL will help you solve
PPTX
UniCredit Leasing uses Applications Manager to deliver seamless services worl...
PPTX
Opmanager technical overview
PPTX
Global Airline giant's application performance monitoring solution!
PPTX
When Your App Hits The Highway - NetFlow Analyzer V10 Overview
PPTX
5 ways you can benefit from OpManager Plus
PPTX
Free training on NCM - Discovery & Disaster recovery
PPTX
Network Configuration Management - Mumbai Seminar
PPTX
Why Configuration Management Matters
PPTX
Simplifying IT operations manament with OpManager
PPTX
Network Traffic Analysis at a financial institution with 788 branches for 350...
PPTX
OpManager Technical Overview
PPTX
New OpManager v12
PPTX
What's new in NetFlow Analyzer 12.2
5 ways you can strengthen and secure your network infrastructure with Firewal...
5 Ways NCM Can Save You From A Disaster
Network and server performance monitoring training
Gulf Chemicals & Metallurgy manages 1700 interfaces with OpManager
Top 5 IT challenges for 2017
IT Solutions Provider in Kosovo uses Bandwidth monitoring, NetFlow Analyzer
Top 5 problems a NETWORK ANALYSIS TOOL will help you solve
UniCredit Leasing uses Applications Manager to deliver seamless services worl...
Opmanager technical overview
Global Airline giant's application performance monitoring solution!
When Your App Hits The Highway - NetFlow Analyzer V10 Overview
5 ways you can benefit from OpManager Plus
Free training on NCM - Discovery & Disaster recovery
Network Configuration Management - Mumbai Seminar
Why Configuration Management Matters
Simplifying IT operations manament with OpManager
Network Traffic Analysis at a financial institution with 788 branches for 350...
OpManager Technical Overview
New OpManager v12
What's new in NetFlow Analyzer 12.2
Ad

Similar to Free Netflow analyzer training - diagnosing_and_troubleshooting (20)

PPTX
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
PPTX
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
PPTX
NetFlow Analyzer Training Part I: Getting the initial settings right
PPTX
How ManageEngine NetFlow Analyzer helped Boston Properties Save Bandwidth Costs
PPTX
Webinar: How to troubleshoot bandwidth hogs and take action.
PPTX
Network Bandwidth management - Mumbai Seminar
PPTX
Export flows, group traffic, map application traffic and more: NetFlow Analyz...
PPTX
Business Intelligent Reporting Process.pptx
 
PPT
nfa_reseller managed engine with very nice explanation
PPT
NetFlow Auditor Anomaly Detection Plus Forensics February 2010 08
PPTX
Splunk MINT for Mobile Intelligence and Splunk App for Stream for Enhanced Op...
 
PPTX
Wikibon #IoT #HyperConvergence Presentation via @theCUBE
PPTX
Hyper-Convergence CrowdChat
PPTX
INT_Ch17.pptx
PPTX
What’s New: Splunk App for Stream and Splunk MINT
 
PPTX
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
 
PPTX
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
 
PPTX
Splunk MINT and Stream Breakout
 
DOC
T7L4.doc.doc
PPTX
The Need for Complex Analytics from Forwarding Pipelines
Bandwidth reporting, capacity planning, and traffic shaping: NetFlow Analyzer...
NetFlow Analyzer Training Part II : Diagnosing and troubleshooting traffic is...
NetFlow Analyzer Training Part I: Getting the initial settings right
How ManageEngine NetFlow Analyzer helped Boston Properties Save Bandwidth Costs
Webinar: How to troubleshoot bandwidth hogs and take action.
Network Bandwidth management - Mumbai Seminar
Export flows, group traffic, map application traffic and more: NetFlow Analyz...
Business Intelligent Reporting Process.pptx
 
nfa_reseller managed engine with very nice explanation
NetFlow Auditor Anomaly Detection Plus Forensics February 2010 08
Splunk MINT for Mobile Intelligence and Splunk App for Stream for Enhanced Op...
 
Wikibon #IoT #HyperConvergence Presentation via @theCUBE
Hyper-Convergence CrowdChat
INT_Ch17.pptx
What’s New: Splunk App for Stream and Splunk MINT
 
New Splunk Management Solutions Update: Splunk MINT and Splunk App for Stream
 
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
 
Splunk MINT and Stream Breakout
 
T7L4.doc.doc
The Need for Complex Analytics from Forwarding Pipelines
Ad

More from ManageEngine, Zoho Corporation (20)

PPTX
Create seamless customer experiences
PDF
From web interface to database: Monitor what matters
PDF
NetFlow Analyzer Free Training Series Part I - May 2020
PDF
Overcome real-time server and VM monitoring challenges
PPTX
Modernizing Cloud and Hyperconverged Infrastructure monitoring
PPTX
Deliver seamless digital experience
PDF
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
PPTX
From web interface to the database:Monitor all that matters
PDF
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
PDF
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
PDF
NetFlow Analyzer Product Overview
PPTX
Monitoring cloud applications and hyperconverged infrastructure
PPTX
Building the right website monitoring strategy
PPTX
Unlock the value of your big data infrastructure
PPTX
Key to optimal end user experience
PPTX
Monitoring cloud applications and containers
PPTX
implementing the right website monitoring strategy
PPTX
Big data and non relational database
PPTX
Visibility-from web application interface to the database
PPTX
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps
Create seamless customer experiences
From web interface to database: Monitor what matters
NetFlow Analyzer Free Training Series Part I - May 2020
Overcome real-time server and VM monitoring challenges
Modernizing Cloud and Hyperconverged Infrastructure monitoring
Deliver seamless digital experience
Free NetFlow Analyzer training Season 1 Part 2 - Feb 2020
From web interface to the database:Monitor all that matters
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - EST
NetFlow Analyzer Training Season 1 Part 1 - Feb 2020 - GMT
NetFlow Analyzer Product Overview
Monitoring cloud applications and hyperconverged infrastructure
Building the right website monitoring strategy
Unlock the value of your big data infrastructure
Key to optimal end user experience
Monitoring cloud applications and containers
implementing the right website monitoring strategy
Big data and non relational database
Visibility-from web application interface to the database
Free OpManager training Part 4 - Monitoring Network Performance and Network Maps

Recently uploaded (20)

PPT
Teaching material agriculture food technology
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
DOCX
The AUB Centre for AI in Media Proposal.docx
 
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPTX
Spectroscopy.pptx food analysis technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
cuic standard and advanced reporting.pdf
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
PDF
Encapsulation theory and applications.pdf
Teaching material agriculture food technology
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
The AUB Centre for AI in Media Proposal.docx
 
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Spectroscopy.pptx food analysis technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Encapsulation_ Review paper, used for researhc scholars
Building Integrated photovoltaic BIPV_UPV.pdf
NewMind AI Weekly Chronicles - August'25 Week I
Programs and apps: productivity, graphics, security and other tools
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Spectral efficient network and resource selection model in 5G networks
cuic standard and advanced reporting.pdf
sap open course for s4hana steps from ECC to s4
Unlocking AI with Model Context Protocol (MCP)
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Optimiser vos workloads AI/ML sur Amazon EC2 et AWS Graviton
Encapsulation theory and applications.pdf

Free Netflow analyzer training - diagnosing_and_troubleshooting

  • 1. Diagnosing and troubleshooting traffic issues faster Free training on NetFlow Analyzer: Part II
  • 2. Welcome to a free training on NetFlow Analyzer!
  • 3. Can you hear me? Can you see the presentation? Please confirm by commenting in the chat panel.
  • 5. Part II Diagnosing and troubleshooting traffic issues faster
  • 6. Agenda • Customizing data storage • Customizing dashboards • Reporting and automation • Troubleshooting with forensics • Traffic shaping • Capacity planning and billing
  • 7. Major concerns while troubleshooting an issue • How do I control how long data is stored for troubleshooting? • How do I identify potential issues early and get alerted about them? • How do I find the root cause of an issue? • How do I troubleshoot and resolve an issue? • How do I optimize traffic and check if my bandwidth is slowly reaching its limit? • How do I know if I'm being overcharged by my ISP?
  • 8. How long data is stored for troubleshooting
  • 9. Customizing storage settings Aggregated dataRaw data One-minute data
  • 10. Aggregated data Default ON Raw data Default OFF Types of data storage • Each and every detail on application, source, destination, and more • Storage time limit (one hour to one month) • By default one day is selected • Improve raw storage up to one year with High Perf • Troubleshoot faster with forensics • Stores "top 100" records for conversation by default (Up to 300 records) • Retains data forever by default • Capacity planning and long-term reporting
  • 12. Benefit of turning on raw data • One-minute granularity for the most detailed traffic analysis • Long-term storage for better root cause analysis • Improves accuracy with each and every conversation detail • Deeper insights for troubleshooting with forensics reports • Real-time alerts to troubleshoot issues immediately http://blogs.manageengine.com/product-blog/netflowanalyzer/2010/01/29/data-storage-pattern-in-netflow-analyzer.html
  • 13. Why you need a High Perf reporting engine database So you can: 1. Handle huge volumes of traffic with raw data 2. Improve accuracy of traffic analysis 3. Generate insightful reports faster 4. Increase your raw data storage period up to one year 5. Follow capacity trends and troubleshoot efficiently
  • 14. One-minute traffic data • Interface traffic graph for any 24-hour period • Capacity planning traffic report • Compare report Raw data • Forensics • Last 2 hour for interface snapshot graphs • Traffic details for App flow, Medianet, Multicast, AVC and ASA flow. Aggregated data • All widgets in inventory (Application, conversation and QoS) • All interfaces and graphs, except a traffic graph for any 24-hour period • Search and custom search report • Consolidated report • Schedule report • Report profile Data storage summary
  • 15. How to identify potential issues early
  • 16. Traffic summary dashboards Top N applicationsDevice summary Top N protocols Top N QoS Top N conversations
  • 17. View top N traffic details from the dashboard • Track top N details in traffic summary • Drill down to the most consumed traffic; identify suspicious traffic • Create new dashboards to view the details that are important to you • Display live data in your NOC screen with auto-refresh option
  • 18. Proactive alerting Link congestionUtilization % exceeds High traffic volume Link speed is low
  • 19. Set alarms based on bandwidth usage • Difference between alarms and events Alarms display: • Message • Source • Category • Technician • Notes • Severity • Date/time
  • 20. Possible options with alarms • Drill down to faulty router/interface from the alarm • Note the exact time an issue occurred • Check for traffic/application graphs • Add notes to update the status of an alarm • Discuss issues with team members An alarm is raised when WAN link utilization is more than 50%
  • 21. How to find the root cause of an issue
  • 22. Easy reporting CompareCustom search Consolidated IP group and protocol Forensics
  • 23. Drill down to any specific detail with reports Search/custom search report Compare report Consolidated report IP group consolidated report Protocol distribution report Bandwidth analysis reports help you: Search specific traffic details by the associated application, protocol, host, or IP Compare bandwidth usage at different time intervals Track top talkers and conversations with a complete report Visualize the combined bandwidth usage of all IP groups View protocol-based traffic for any particular interface
  • 24. Save all your reports in Report Profiles
  • 25. Benefits of reporting • Create criteria-based reports to identify bandwidth shortages or traffic spikes • Automate and schedule reports at any specific time; receive notifications about reports • Save reports and export them to PDF or CSV files to share them with upper management • Generate historical reports to promptly diagnose bandwidth capacity • Periodically review and optimize the usage of network bandwidth
  • 26. Troubleshooting with forensics What's the root cause of a traffic spike?
  • 27. Benefits of forensics • Get more granular traffic statistics using raw data • Drill down to identify which users, applications, and protocols are consuming the most bandwidth at a specific time • Troubleshoot accurately by defining multiple criteria to filter required traffic • Flexibility to review historical data and find out why a particular spike was generated
  • 29. There was major network congestion and critical applications were running slowly...
  • 31. ...which affected all users connected to the network. The biggest challenge was figuring out how to quickly resolve the issue. Step 1: Determine which part of the network was experiencing congestion Step 2: Identify what caused the congestion. App or user or external attack? Step 3: Troubleshoot by applying policies and bring the network back up
  • 32. Step 1: Determine which part of the network was experiencing congestion • Where is the congestion and is it notified to me? • Which applications were contributing to the most traffic? • What QoS precedence value was the traffic utilizing at the time? • What were the top source, destination & conversations in the network? The dashboard immediately provided details on what was being affected.
  • 33. Step 2: Use forensics to identify what caused the congestion • Which applications or users were consuming the most traffic? • What was the top conversation in the network at that time? Forensics help locate the real cause. The issue was with a patch management upgrade that happened on all windows server during business hours.
  • 34. 1. Block the IP using an access control list (ACL) 2. Reduce the traffic bandwidth utilization 3. Load share the traffic with the help of Compare Reports 4. Reschedule the action to occur during non-business hours How to troubleshoot and fix the issue
  • 35. 1. Filter out excess router traffic by blocking IP/ IP network 2. Allow certain packets and deny everything else #1. Block the IP with an ACL
  • 36. 1. Tweak your traffic policies with CBQoS configurations 2. Shape interface traffic and prioritize your critical applications 3. Monitor the policy change in CBQoS graphs #2. Reduce the traffic bandwidth utilization
  • 37. 1. Compare multiple devices across the same time period to view each one's capacity 2. Decide how much to deviate traffic on each interface/device #3 and #4: Load share the traffic or rescheduling using Compare Reports
  • 38. Once the issue is resolved, generate a consolidated report to view the traffic stats.
  • 39. What should you do if your bandwidth is slowly reaching its limit?
  • 40. Capacity planning Know immediately when you've reached your maximum capacity. Generate short-term or long-term reports to view your network's usage trends. Get meaningful insight into application growth, average usage, and any usage deviations.
  • 41. How to bill your customers correctly
  • 42. Billing Measure bandwidth usage to cross-check with your ISP billing. Generate bill plans for your customers/clients if you're an ISP.
  • 47. Q&A