Interpreting NNA Data
Posted: Fri Mar 17, 2017 9:43 am
Hey Everyone, I believe I am having an issue interpreting, correlating data from Network Analyzer, or possibly a bug?
I am having NetFlow sent to my NNA virtual machine, from a cluster of Fortigate 800C's. The data is getting to NNA efficiently as well. I'll just list some questions:
1) When I look at the summary screen of my Firewall, I see the bandwidth graph, picture below (Bandwidth Graph). What exactly am I looking at? Per the image, if I highlight a part of the graph is shows me a date/timestamp with Bytes: 1713.1 GB. Is this saying, at this exact time that much data has went over my interface?
2) In a similar sense, if I look at my sources screen it shows the small bar graph to visualize traffic, picture below (Sources). If I highlight the graph it says Traffic 15 Minutes Ago: 6.36 TB; again what is this saying, 15 minutes ago from that time I had 6 Terabytes of data across an interface?
3) In another picture (Apple TV), I did a simple query to see traffic going to one of my Apple TV's in my office. As you can see in the picture is says for a period of less than 24 hours the Apple TV has used almost 6 1/2 TB's of data, then to the bottom left in it says "Total Bytes" is almost 13 TB's. coincidentally this "total" number is exactly double the Bytes resulting in the query. In this same picture it says showing the last 24 hours, however it isn't...Am I reading this incorrectly or is NNA having a problem with Bytes and Bits?
I appreciate any help,
By all means if someone can direct me to another post please do. I have watched many many videos and webinars etc, with no real luck of explaining this to me.
I am having NetFlow sent to my NNA virtual machine, from a cluster of Fortigate 800C's. The data is getting to NNA efficiently as well. I'll just list some questions:
1) When I look at the summary screen of my Firewall, I see the bandwidth graph, picture below (Bandwidth Graph). What exactly am I looking at? Per the image, if I highlight a part of the graph is shows me a date/timestamp with Bytes: 1713.1 GB. Is this saying, at this exact time that much data has went over my interface?
2) In a similar sense, if I look at my sources screen it shows the small bar graph to visualize traffic, picture below (Sources). If I highlight the graph it says Traffic 15 Minutes Ago: 6.36 TB; again what is this saying, 15 minutes ago from that time I had 6 Terabytes of data across an interface?
3) In another picture (Apple TV), I did a simple query to see traffic going to one of my Apple TV's in my office. As you can see in the picture is says for a period of less than 24 hours the Apple TV has used almost 6 1/2 TB's of data, then to the bottom left in it says "Total Bytes" is almost 13 TB's. coincidentally this "total" number is exactly double the Bytes resulting in the query. In this same picture it says showing the last 24 hours, however it isn't...Am I reading this incorrectly or is NNA having a problem with Bytes and Bits?
I appreciate any help,
By all means if someone can direct me to another post please do. I have watched many many videos and webinars etc, with no real luck of explaining this to me.