I have read a few posts on here about the various channel in a netflow sensor. I have been working on this a couple of days and I have included the standard channels and the list that another poster had compiled which appeared to be pretty comprehensive. I gave it a day to bake so to speak and I am still seeing a huge amount of traffic hit that various channel. My question is how to see what traffic is is being sent to it in order to create custom channels to spread that out. If the various traffic was very low on the list, I probably wouldn't even worry about it. However, it is like the second entry on my toplist for protocols. Very frustrating. Any ideas?


Article Comments

Hello,

Thank you very much for your KB-Post. To see the details of the traffic categorized as 'Various', you could enable the "Log Stream Data to Disk"-Feature ("Only for the 'Other' channel)"in the Settings of the sensor, and then check the CSV-File.

best regards.


Oct, 2016 - Permalink