v9.0 Alarm Flowalyzer Poller: Missed Polls

Across hundreds of flow exporting routers and switches, Flow Analytics™ delivers on:
Top conversations, top applications, top source and destination hosts by bytes, top source and destination hosts by flows, total number of unique hosts, the total number of unique applications, internal threats and several other informative statistics

The NBA portion of Flow Analytics™ delivers on:
Which assets are under attack? What threats are being missed? Users which may not be following corporate policy. Helpful information to determine if the business is in compliance with regulations. Fast searching through massive amounts of data. Monitoring to ensure that the existing infrastructure investments are adequate. Details so that you can target areas to improve the security posture.

Moderators: scottr, Moderator Team

v9.0 Alarm Flowalyzer Poller: Missed Polls

Postby awysocki » Wed Feb 01, 2012 3:41 pm

I'm getting an alarm with the following description:
plixer_flowalyzer_svc[2240]: Device 10.x.x.x is unreachable

I'm seeing the same alarm for 3 devices which are outside of firewalls. This alert only started since the upgrade. The source shows 127.0.0.1 (the server itself I'm assuming). What does this alert mean, and is there a new feature which I'm missing which I need to open up on the firewall between these devices? All other devices (not behind this firewall) are not reporting this error.

Thanks,
Andrew
awysocki
 
Posts: 8
Joined: Mon Jan 11, 2010 1:21 pm

Re: v9.0 Alarm Flowalyzer Poller: Missed Polls

Postby scottr » Wed Feb 01, 2012 3:59 pm

Hello Andrew,

Version 9 now includes a polling function that goes out and checks up/down status as well as RTT. You can set this up to poll not only your netflow sending devices, but any device that you add to the poller list, or add as an object in a map.

This polling function is now part of FlowAlyzer and does reside on the Scrutinizer server.

The missed polls is that the device was unreachable.

Scott
User avatar
scottr
 
Posts: 64
Joined: Mon Oct 05, 2009 12:22 pm

Re: v9.0 Alarm Flowalyzer Poller: Missed Polls

Postby awysocki » Wed Feb 01, 2012 4:36 pm

Thanks Scott, I found the issue and allowed the device to ping the specific subnet on the firewall. Is there some supporting documentation on this feature outside of Scrutinizer (or within)?
awysocki
 
Posts: 8
Joined: Mon Jan 11, 2010 1:21 pm

Re: v9.0 Alarm Flowalyzer Poller: Missed Polls

Postby scottr » Thu Feb 02, 2012 9:47 am

Hello,

This poller runs as part of flowalyzer. You can configure devices either by adding objects to a map, or opening flowalyzer itself from the START button. In flowalyzer there is a poller tab where you can add/remove devices.

We by default configure all of your flow sending devices and poll them.

As far as help docs, if you hit the ? icon you can find some overall information. But it does not go into set-up.

Scott
User avatar
scottr
 
Posts: 64
Joined: Mon Oct 05, 2009 12:22 pm


Return to Flow Analytics

Who is online

Users browsing this forum: No registered users and 0 guests

Who is online

In total there are 0 users online :: 0 registered, 0 hidden and 0 guests (based on users active over the past 5 minutes)
Most users ever online was 60 on Thu Jun 25, 2009 9:07 am

Users browsing this forum: No registered users and 0 guests