Reduce and Analyze Traffic with Advanced Filtering
Advanced filters enable you to isolate traffic by protocol, domain, application, and so on. For example, the following visual demonstrates how to isolate BOOTP request traffic (in other words, client devices requesting an IP address from a BOOTP Server on their network segment).
: Click the arrows button () to exclude/include the specified filter pattern.
: For filtering on an IP address, you can use CIDR notation to identify a subnet of hosts from which the reports display data. For example, when you select a Sender filter type, you can specify a subnet using 192.168.11.0/24 to display information from all of the hosts in the subnet.
- . Show traffic sent by the specified device. You can match a device using its host name or its IP address.
- . Show traffic received by the specified device. You can match a device using its host name or its IP address.
- . Show traffic that used the specified protocol (for example, UDP, TCP, or ICMP).
- . Show traffic that used the specified type of service.
- . Show traffic that used the specified application. The keyword must match the application name as configured in the NTA Applications Library.
: You can enter a port number instead of an application name to show all traffic transmitting over a certain port.
- . Show traffic sent by hosts on the specified domain.
- . Show traffic received by hosts on the specified domain.
- . Show traffic sent by devices whose IP addresses are registered to a country, state, subdivision, or city.
- . Show traffic received by devices whose IP addresses are registered to a country, state, subdivision, or city.
- . Show traffic sent by the specified group.
- . Show traffic received by the specified group.
- . Show traffic sent by domains that have the specified top level domain (such as .com, .net, .us, or .uk).
- . Show traffic received by domains that have the specified top level domain (such as .com, .net, .us, or .uk).
- . Show traffic by ICMP type.
- . Show traffic by packet size.
- . Show traffic by sender Autonomous System Number (ASN).
- . Show traffic by receiver Autonomous System Number (ASN).
- . Show traffic by NBAR classified application.
- . Show traffic by port number.