Setting Up Flow Analytics (FA)

FA algorithms are executed sequentially. Most of them do not run until one or more NetFlow exporters are added to the individual algorithms.

To add exporters to an algorithm, visit Admin > Settings > Flow Analytics Configuration and click on an algorithm name listed in the table.

At the top of the Flow Analytics Configuration table, it displays the overall time to run all algorithms and the total count of violations across all algorithms.

FA Configuration Columns

  • Down Arrow Menu: This action menu provides several options:

    • Modify the Exporters this Algorithm runs against: Many algorithms do not need to run against all exporters. Visit the Algorithm Strategy page to learn more about types of flows to send to each algorithm.
    • Modify the Hosts Excluded from violating this Algorithm: Use this utility to exclude IP addresses and portions of hostnames that are triggering false positives.
    • View the Run Time Trend for this Algorithm: View a report that displays how long the algorithm takes the run each time it is executed.
    • View the Violation Count Trend for this Algorithm: View a report that indicates how frequently the algorithm is triggering for a matching event.
  • Mouse over columns to learn what they do.

  • Round Icon: This icon indicates the status of the algorithm using different colors. Mouse over the icon and the tool tip that appears will explain the status.

  • Name: This is the name of the algorithm that is checking for abnormal behaviors. Click on the algorithm name to modify the settings, apply exporters or change the exclusions for the algorithm.

  • Time: This is the amount of time the algorithm takes to run across all selected routers/switches.

  • Count: This is the number of violations found the last time the algorithm ran. Click on the number to view graphs for longer time periods.

  • Time exceeded: Algorithms that exceed the configured run time will be cancelled.

Important Notes:

  • Add only a few routers to a few algorithms initially and start off slowly. Pay attention to the Vitals of the server. After 15-30 minutes add a few more routers to selected algorithms and slowly ramp up the FA deployment.
  • FA has only 300 seconds (i.e. 5 minutes) to finish all enabled algorithms. If it can’t finish in 300 seconds, it will stop where it is and start over. All algorithms must finish within 5 minutes as the process repeats every 5 minutes. Optimize performance by paying attention to the time each algorithm takes to run as well as the overall time shown at the very top of the Flow Analytics Configuration gadget.
  • Check out these other FA optimization tips.