Exclusions - wildcards.

Across hundreds of flow exporting routers and switches, Flow Analytics™ delivers on:
Top conversations, top applications, top source and destination hosts by bytes, top source and destination hosts by flows, total number of unique hosts, the total number of unique applications, internal threats and several other informative statistics

The NBA portion of Flow Analytics™ delivers on:
Which assets are under attack? What threats are being missed? Users which may not be following corporate policy. Helpful information to determine if the business is in compliance with regulations. Fast searching through massive amounts of data. Monitoring to ensure that the existing infrastructure investments are adequate. Details so that you can target areas to improve the security posture.

Moderators: scottr, Moderator Team

Exclusions - wildcards.

Postby afo8n » Mon Dec 13, 2010 11:10 am

Hey all.

Looking to exclude not one host but a subnet from certain analytics. Can't seem to figure out the syntax.

Is this possible?

Thanks for any help...
Alan
afo8n
 
Posts: 2
Joined: Mon Dec 13, 2010 11:07 am

Re: Exclusions - wildcards.

Postby pauld » Mon Dec 13, 2010 11:30 am

Hi afo8n,

When you're running a report you can add both inclusion and exclusion filters, so what you'll want to do is add a "Subnet" filter and then click the small green square so it turns red which makes it an exclude filter.

If you're having trouble finding the button I'm talking about, take a look at #2 on this blog about the Top 5 Scrutinizer features you never use.

Let me know if you have any questions.

Thanks,
Paul
User avatar
pauld
 
Posts: 156
Joined: Mon Jan 04, 2010 10:05 am
Location: Sanford, Maine

Re: Exclusions - wildcards.

Postby afo8n » Mon Dec 13, 2010 11:38 am

Hey Paul.

Thanks for the info. Am looking to accomplish this within Flow Analytics (FA), not Scrutinizer. Am using the Flow Analytics exclusion gadget to do so.

Objective is to have certain subnets or ranges of IP's excluded from specific FA algorithms in order to decrease the number of false positives.

Pardon me if I am incorrect - this is my second day with the product.

Thanks for the help...
afo8n
 
Posts: 2
Joined: Mon Dec 13, 2010 11:07 am

Re: Exclusions - wildcards.

Postby mkrygeri » Mon Dec 13, 2010 11:51 am

Hi afo8n,
Unfortunately, subnet exclusions are not yet available in FA.


-MikeK
mkrygeri
 
Posts: 87
Joined: Tue Aug 02, 2005 8:47 am

Re: Exclusions - wildcards.

Postby pauld » Mon Dec 13, 2010 11:54 am

Hi afo8n,

Currently, you can't add Flow Analytics exclusions by subnet. We really value customer feedback so what I'm going to do is open up a feature request with development to add this functionality.

Let me know if there's anything I can help with.

Thanks,
Paul
User avatar
pauld
 
Posts: 156
Joined: Mon Jan 04, 2010 10:05 am
Location: Sanford, Maine

Re: Exclusions - wildcards.

Postby filobeddo » Wed Jun 22, 2011 7:03 am

I was going to start a thread requesting this but read this one and so will second this feature request.

Having just started using FA I quickly saw I would ideally need to exclude subnets from FA alarms, for example I have 2 subnets populated with CCTV cameras which all multicast as part of their normal operation.
These are creating alarm events from FA. Excluding them one by one is not practicle for the number I have.

Hope to see this on a future maintenance release.

Thanks!
filobeddo
 
Posts: 10
Joined: Fri Apr 08, 2011 8:27 am
Location: London, England

Re: Exclusions - wildcards.

Postby mattstjean » Wed Jun 22, 2011 7:29 am

Thank you for the reply, filobeddo.

I have added your feature request for review by our developers. Feel free to shoot any other great ideas our way!
User avatar
mattstjean
 
Posts: 3
Joined: Tue May 31, 2011 10:41 am


Return to Flow Analytics

Who is online

Users browsing this forum: No registered users and 0 guests

cron

Who is online

In total there are 0 users online :: 0 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 60 on Thu Jun 25, 2009 9:07 am

Users browsing this forum: No registered users and 0 guests