In Data menu, there are main functions for traffic analysis.
History.
If you have enabled JavaScript functionality it's possible to use previously
entered values in the dialog windows. If you would like to open a new history dialog
window click on the icon
located next to the selected field. The history dialog window will contain the last
30 entered values. The following window is an example of protocol history. If you want
to clear the protocol history click on the "clear history" link.
Trends are the most used menu in the whole system. This menu can run all wanted statistics. List of available statistics depends on selected table fields.
To select table in "Table selector" first select the collector and then the table that you want to see. If you haven't enabled JavaScript, please, click on the "Select" button to choose the collector and then the wanted table. Your selection will be displayed in the information window below.
In "General parameters" first select one of the following statistic:
The next options are related to formatting output, you can select if you want to generate a graph, table or both and what types of graph you want to see.
In the "time field" you can specify the time interval that you see.
For example the tenth hourly table is: 10:20-10:45, and the weekly
table is: 2006/02/15 - 2006/02/17. The list of times is separated by a
comma. Click on the icon
to display history window.
In the "bytes or packets field" you can specify which bytes or packets range you want to see. For example if you type in packet field value: 1 you will only see flows where only one packet is transferred.
In "protocols field" you can specify which protocols are seen. For example:
TCP, UDP. The list of protocols is separated by a comma. A complete list
of protocols is located in the system file /etc/protocols
.
Click on the icon
to view list of defined
protocols, applications or detected interfaces.
In applications field you can specify which applications you want to see.
Applications field can have the following formats:
In "TCP flags" you can specify flags which you want to see.
TCP flags field consists of one or two sets of characters <SAFRPU*> <SAFRPU*>
separated by a space. Where character S
stands for TCP flag synchronization,
A
for acknowledgment, F
for finish, R
for reset, P
for push, U
for urgent and *
means all of the above. The first set of characters indicates which TCP flags must be set up,
the second indicates which TCP flags you are checking.
Examples:
![]() | Note |
---|---|
If you enter only one set of characters (e.g. SA), the second is automatically set to "*". |
The TOS byte in the IPv4 header has had various purposes over the years, and has been defined in different ways by five different RFCs ( RFC 791, RFC 1122, RFC 1349, RFC 2474, and RFC 3168). The modern definition of the TOS byte is a six-bit Differentiated Services Code Point and a two-bit Explicit Congestion Notification field. For a full history of the TOS byte, see section 22 of RFC 3168.
Current CFI version accepts the following values:
where P0-7
means precedence value, character 'D
'
means minimize delay, character 'T
' means maximize throughput
and character 'R
' means maximize reliability.
You can use arithmetic logic between source and destination window. Possible values are:
In "Optional parameters" you can: disable domain names resolving, disable counting of total sums, enable displaying of residual part (residue of top ten), displaying exact size values (bytes instead of kilo or mega bytes equivalent) or convert byte values to the bits per second. You can specify link capacity that will be displayed in the graph. Link capacity is in the bits per second, but you can use values in kilobits or megabits, for example 10m means ten megabits per second.
Fields in source or destination windows can be different depending on the selected table.
The following are able to be viewed:
All previous types can be combined. Field separator can be comma or
semicolon. You can also use an exclude character '!
'
which excludes single IP or range of IP from the list.
![]() | Warning |
---|---|
Domain names can't be used when you use IP address ranges! |
After completing the search conditions, you can start searching by clicking on the "Search" button or you can save search conditions in the trends profile by clicking on the "Save to profile" button. After saving conditions you will see information window (see picture bellow).
The pictures below show various examples of search results formatted into a graph.
This product offers various formats of search results. One of these options is format to table. An example of this is shown in the following picture:
Output data can be exported into CSV formatted file. This file can be opened in other applications for example in Microsoft Excel or in Open Office package. When you click on link "Export" in the left dialog menu, an export window will be displayed. You can then specify filename, time format and field header.
For time format you can use the codes listed bellow:
For example you can use time format: %x %X.
You can find a complete list of time formats in PHP documentation. Check web page: http://www.php.net/manual/en/function.strftime.php.
Export is saved into a temporary file. You can download this file via main menu "Exports". After successfully downloading it is recommended deleting this file to save disk space.
This feature allows you to send output data via SMTP protocol to a specific email address. When you click on the "Email results" link in the left dialog menu, an email window will be displayed. You can then specify an email address, subject and comment.