6. Monitoring and alerts
• Syslog
• SNMP
• NetFlow
•
• We have only one case that we set rate-limiting for
continuous heavy downloading
APRICOT2017 6
the client and transmitted bytes: 2001:df9:0:1:xxx:xxx:xxx:xxx 1289045889
Top 5 Src Port ordered by bytes:
Date first seen Src Port Packets(%) Bytes(%) bps
2017-02-28 12:36:32.010 443 916457(97.8) 1.3 G(97.9) 9.4 M
2017-02-28 12:49:34.160 993 20882( 2.2) 26.6 M(2.1) 2.0 M
Summary: total flows: 72, total bytes: 1289045889, total packets: 937388
avg bps: 9550875, avg pps: 868, avg bpp: 1375
Time window: 2017-02-28 12:23:39 - 2017-02-28 12:54:43