Hi,
When I get the data issues ironed out (see previous thread), I am also having a hard time how to actually create the kinds of reports we need.
The Netflow traffic received by nprobe is aggregate traffic consisting of traffic from all our remote locations, showing each individual device inside those LANs.
The type of graph shown when going to Interfaces -> Netflow collector interface -> historical chart page is exactly what I need to see, but it needs to be filtered by subnet so I can see traffic belonging to just that group of hosts.
I can't use the Hosts -> Hosts overview because this shows me the individual computers at the remote locations. We don't use NAT so there isn't a single host entry that corresponds to their router's WAN interface. Also, hosts don't seem to have a historical timeseries type chart like Interfaces does. The pie chart on a host's Protocols page isn't useful - we need the graphs according to time of day. The Protocols page does have a link at the very bottom to a historical reports page (host.details.lua?host=IP&page=historical) but those pages are blank. Maybe this needs to be enabled somewhere but I haven't found the setting yet.
I tried using the "Traffic Report" as well but all it lets me specify is interfaces and protocols as filters. What I miss is the ability to add subnets to drill down to specific locations only.
Is any of this possible with ntopng or am I trying to make it do something that it's not designed to do?
Thanks,
Gerard Beekmans
Sr. Network Engineer
First Nations Technical Services Advisory Group Inc.
Phone: 780-638-2739
Fax: 780-483-8632
Helpdesk: 1-888-999-3356
Email: gbeekmans@tsag.net<mailto:gbeekmans@tsag.net>
Santa Fe Plaza
18232 - 102 Avenue NW
Edmonton, AB T5S 1S7
http://www.tsag.net<http://www.tsag.net/>
When I get the data issues ironed out (see previous thread), I am also having a hard time how to actually create the kinds of reports we need.
The Netflow traffic received by nprobe is aggregate traffic consisting of traffic from all our remote locations, showing each individual device inside those LANs.
The type of graph shown when going to Interfaces -> Netflow collector interface -> historical chart page is exactly what I need to see, but it needs to be filtered by subnet so I can see traffic belonging to just that group of hosts.
I can't use the Hosts -> Hosts overview because this shows me the individual computers at the remote locations. We don't use NAT so there isn't a single host entry that corresponds to their router's WAN interface. Also, hosts don't seem to have a historical timeseries type chart like Interfaces does. The pie chart on a host's Protocols page isn't useful - we need the graphs according to time of day. The Protocols page does have a link at the very bottom to a historical reports page (host.details.lua?host=IP&page=historical) but those pages are blank. Maybe this needs to be enabled somewhere but I haven't found the setting yet.
I tried using the "Traffic Report" as well but all it lets me specify is interfaces and protocols as filters. What I miss is the ability to add subnets to drill down to specific locations only.
Is any of this possible with ntopng or am I trying to make it do something that it's not designed to do?
Thanks,
Gerard Beekmans
Sr. Network Engineer
First Nations Technical Services Advisory Group Inc.
Phone: 780-638-2739
Fax: 780-483-8632
Helpdesk: 1-888-999-3356
Email: gbeekmans@tsag.net<mailto:gbeekmans@tsag.net>
Santa Fe Plaza
18232 - 102 Avenue NW
Edmonton, AB T5S 1S7
http://www.tsag.net<http://www.tsag.net/>