Country filtered view
Using the Flow Navigator, you can customize a filter that will enable you to display network traffic connected with a specified country of origin or destination.
- Click My Dashboards > NetFlow > NTA Summary.
- Click Flow Navigator on the left edge of the summary view. The Flow Navigator is available on any default NTA view.
-
Specify the View Type:
- If you want a filtered view of all countries across your network, click Summary, and then select Countries.
- If you want a filtered view of traffic from or to a specified country connected with a specific node and interface, click Detail, and then select Country.
- Select the Node for which you want to monitor network traffic attributed to a country.
If you select a node here, you can specify only Ingress or Egress for the Flow direction. Selecting Both results in applying the flow direction default for the appropriate view.
- If you want to further limit the view, specify the Interface for which you want to monitor network traffic attributed a country.
- Select a country.
-
Select the Time Period over which you want to view network traffic by country of origin or destination.
Time period options- Select Named Time Period, and select a time period.
- Select Relative Time Period, and provide a number appropriate for the selected time units. The relative time period is measured with respect to the time at which the configured view is loaded.
- Select Absolute Time Period, and provide the start and end time periods.
-
Select a Flow Direction.
Flow direction options- Select Both to include ingress and egress traffic in the calculations NTA makes.
- Select Ingress to include only ingress traffic in the calculations NTA makes.
- Select Egress to include only egress traffic in the calculations NTA makes.
- You can also further limit the view by including or excluding some of the following items:
Applications
If you want to limit your view to only display network traffic to and from applications, or to exclude traffic to and from them, expand Applications, and then complete the following steps:
- If you want to include traffic from specified applications, select Include.
- If you want to exclude traffic from specified applications, select Exclude.
- Enter the name of an appropriate application or the appropriate port number.
- If you want to include or exclude another application, click Add Filter, and then enter the name of the appropriate application.
Autonomous systemsTo only display network traffic to and from autonomous systems, or to exclude traffic to and from certain autonomous systems, expand Autonomous Systems, and enter the ID of an appropriate autonomous network. Click Add Filter.
Autonomous system conversationsTo only display network traffic related to specific autonomous system conversations, or to exclude traffic to and from them, expand Autonomous System Conversations, and enter IDs of autonomous systems involved in conversations. Click Add Filter.
ConversationsTo only display network traffic related to specific conversations between two endpoints, or to exclude traffic to and from them, expand Conversations and enter the endpoints involved in the conversation. Click Add Filter.
DomainsTo only display network traffic related to specific domains, or to exclude traffic to and from them, expand Domains, and enter the domain name you want to Include or Exclude.
- To add multiple domains, enter a name and then click Add Filter to apply your selection after each entry.
- If a domain name is not resolved and saved in NTA, you cannot use it in the Flow Navigator. In this case, NTA will prompt you for a valid name. For more information about resolving domain names, see Host and domain names in SolarWinds NTA
EndpointsTo only display network traffic related to specific endpoints, or to exclude traffic to and from them, expand Endpoints:
- Enter the IP address or hostname of an appropriate endpoint to Include or Exclude.
- If you want to include or exclude traffic from a specified subnet, enter the appropriate range of IP addresses.
You can either type in the range, for example
192.168.1.0-192.168.1.255
, or use the CIDR notation, for example192.168.1.0/24
. - If you want to include or exclude another endpoint, click Add Filter, and then enter the name of an appropriate endpoint.
IP address groupsTo only display network traffic related to specific IP address groups, or to exclude traffic to and from them, expand IP Address Groups, and then complete the following steps:
- Enter an appropriate IP address group.
Though an IP Address Group is disabled, it may continue to appear in the list. As a workaround, rename the group before disabling it. For example, for an IP Address Group called
PrimaryLAN
, you might add_DISABLED
to the end. An entry calledPrimaryLAN_DISABLED
indicates that the group is inactive. - If you want to include or exclude another IP address group, click Add Filter, and then enter the name of an appropriate IP address group.
IP address group conversationsTo only display network traffic related to conversations between specified IP address groups, or to exclude traffic to and from them, expand IP Address Group Conversations:
- Select the IP address groups involved in conversations that you want to include or exclude.
- If you want to include or exclude another IP address group conversation, click Add Filter, and then enter the appropriate conversation IP address groups.
ProtocolsTo only display network traffic using specific protocols, expand Protocols and select the protocol to Include or Exclude.
If you want to include or exclude another protocol, click Add Filter, and then select another protocol.
Types of serviceTo only display network traffic using specific service types, expand Types of Service and select an appropriate type of service to Include or Exclude.
If you want to include or exclude another type of service, click Add Filter, and then select another type of service.
- Click Submit.
- If you want to save your custom filtered view for future reference, click Save Filtered View to Menu Bar.