Problem Accessing Historical Data
Moderators: scottr, Moderator Team
5 posts
• Page 1 of 1
Problem Accessing Historical Data
Hi,
We are busy trailing Scrutinizer.
If I search for an IP address and leave the period for the last hour or so, it finds data. However, if I change to period to something else such as last 24 hours, last week etc, it doesn't find any data for the host.
Am I missing something obvious?
We are busy trailing Scrutinizer.
If I search for an IP address and leave the period for the last hour or so, it finds data. However, if I change to period to something else such as last 24 hours, last week etc, it doesn't find any data for the host.
Am I missing something obvious?
- steven99
- Posts: 2
- Joined: Mon Jul 04, 2011 10:52 am
Re: Problem Accessing Historical Data
Hello, There is a very good reason for this. If the volume of flows from the device is significant and the end system is a low volume traffic producer, the "roll up" process in Scrutinizer may end up dropping all of the data from the end system you are trying to find in the larger intervals.
http://www.plixer.com/blog/netflow-anal ... tated-why/
http://www.plixer.com/blog/netflow-anal ... tated-why/
Michael Patterson
Scrutinizer Product Manager
(207)324-8805 x222
Bio: viewtopic.php?f=20&t=1296
Blogs: http://www.plixer.com/blog/author/mikeplixercom/
Twitter: http://twitter.com/netflowpm
Scrutinizer Product Manager
(207)324-8805 x222
Bio: viewtopic.php?f=20&t=1296
Blogs: http://www.plixer.com/blog/author/mikeplixercom/
Twitter: http://twitter.com/netflowpm
-

mpatters - Posts: 248
- Joined: Mon Oct 30, 2006 11:27 pm
- Location: Sanford, Maine
Re: Problem Accessing Historical Data
Ok, thanks for that link, makes some sense now.
So, if I need to search for an IP that is dropped by the roll up, but I am not sure of the exact time frame (e.g sometime in the last 24 hours), is there any way I can search for it?
So, if I need to search for an IP that is dropped by the roll up, but I am not sure of the exact time frame (e.g sometime in the last 24 hours), is there any way I can search for it?
- steven99
- Posts: 2
- Joined: Mon Jul 04, 2011 10:52 am
Re: Problem Accessing Historical Data
Steven99,
No there isn't a way to do that. you might need to guess the time frame and keep adding a filter for that IP until you find the conversations you are looking for. Also note that since the IP has been dropped as a result of roll-ups, you might want to set granularity to 5m or 1m each time.
http://www.plixer.com/blog/scrutinizer/ ... reporting/
No there isn't a way to do that. you might need to guess the time frame and keep adding a filter for that IP until you find the conversations you are looking for. Also note that since the IP has been dropped as a result of roll-ups, you might want to set granularity to 5m or 1m each time.
http://www.plixer.com/blog/scrutinizer/ ... reporting/
- dalet0
- Posts: 41
- Joined: Mon May 17, 2010 10:52 am
- Location: Biddeford, ME
Re: Problem Accessing Historical Data
Are you all set?
- dalet0
- Posts: 41
- Joined: Mon May 17, 2010 10:52 am
- Location: Biddeford, ME
5 posts
• Page 1 of 1
Who is online
Users browsing this forum: No registered users and 0 guests