Problem Accessing Historical Data

Scrutinizer is an enterprise/business class NetFlow and sFlow analysis tool. Scrutinizer provides historical trends of the company's critical network interfaces as well as the details on:

Who: The end system causing the traffic
What: The application/protocol that is being used
When: The time frame it has been occurring for
Where: The network connection that is affected

Moderators: scottr, Moderator Team

Problem Accessing Historical Data

Postby steven99 » Mon Jul 04, 2011 10:55 am

Hi,

We are busy trailing Scrutinizer.

If I search for an IP address and leave the period for the last hour or so, it finds data. However, if I change to period to something else such as last 24 hours, last week etc, it doesn't find any data for the host.

Am I missing something obvious?
steven99
 
Posts: 2
Joined: Mon Jul 04, 2011 10:52 am

Re: Problem Accessing Historical Data

Postby mpatters » Mon Jul 04, 2011 7:48 pm

Hello, There is a very good reason for this. If the volume of flows from the device is significant and the end system is a low volume traffic producer, the "roll up" process in Scrutinizer may end up dropping all of the data from the end system you are trying to find in the larger intervals.
http://www.plixer.com/blog/netflow-anal ... tated-why/
Michael Patterson
Scrutinizer Product Manager
(207)324-8805 x222
Bio: viewtopic.php?f=20&t=1296
Blogs: http://www.plixer.com/blog/author/mikeplixercom/
Twitter: http://twitter.com/netflowpm
User avatar
mpatters
 
Posts: 248
Joined: Mon Oct 30, 2006 11:27 pm
Location: Sanford, Maine

Re: Problem Accessing Historical Data

Postby steven99 » Tue Jul 05, 2011 4:20 am

Ok, thanks for that link, makes some sense now.

So, if I need to search for an IP that is dropped by the roll up, but I am not sure of the exact time frame (e.g sometime in the last 24 hours), is there any way I can search for it?
steven99
 
Posts: 2
Joined: Mon Jul 04, 2011 10:52 am

Re: Problem Accessing Historical Data

Postby dalet0 » Tue Jul 05, 2011 9:08 am

Steven99,

No there isn't a way to do that. you might need to guess the time frame and keep adding a filter for that IP until you find the conversations you are looking for. Also note that since the IP has been dropped as a result of roll-ups, you might want to set granularity to 5m or 1m each time.

http://www.plixer.com/blog/scrutinizer/ ... reporting/
dalet0
 
Posts: 41
Joined: Mon May 17, 2010 10:52 am
Location: Biddeford, ME

Re: Problem Accessing Historical Data

Postby dalet0 » Mon Aug 08, 2011 6:29 am

Are you all set?
dalet0
 
Posts: 41
Joined: Mon May 17, 2010 10:52 am
Location: Biddeford, ME


Return to Scrutinizer

Who is online

Users browsing this forum: No registered users and 0 guests

Who is online

In total there are 0 users online :: 0 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 60 on Thu Jun 25, 2009 9:07 am

Users browsing this forum: No registered users and 0 guests