Suspicious Connections Report

Suspicious Connections Report report reveals traffic and conversations with IP addresses identified in blacklist databases or tracked using the IP Reputation Library.

Note: You add tracking of suspicious IPs using Internet community resources such as Tor lists from the IP Reputation Library.

suspisciousConnections

To display Flow and Packet measurements, click a column heading () for column selection list (). You can also include:

Generate a report

Choose source. , Choose a networking device or single physical or virtual interface you want to see Suspicious Connections Report measurements for. Choose traffic direction across an interface.

Choose time constraints. DateRange Choose times for the Suspicious Connections Report. (Subject to NTA collection interval and retention policies.)

Choose, filter, and reorder columns. Choose and hide columns, reorder columns, and apply advanced filters to customize your data view.

Chart, adjust output, and visualize. WUG17.0N-SP2-REPORTS-SETTINGS-IMG Apply chart, geo mapping (World Map), and display options in Report Settings WUG17.0N-SP2-REPORTS-SETTINGS-IMG dialog (optional).

Export report data

Report data can be exported from WhatsUp Gold, reused, and distributed in multiple formats. Select Expand (Full_Screen_Transparent) from the Dashboard Options (DasboardOptions) menu. After the report has been expanded, select the Export Data icon to access the following options:

See Also

Network Traffic

Working with NTA reports using the world map

Receivers

Senders

Top Cities

Top Conversations Between Cities

Interface Usage

NBAR Applications - Flow Details

NBAR Applications - Interface Totals

NTA Types of Services (ToS)

Packet Size Distribution

Top Ports

Top Protocols

Top Applications

Top Conversations

Top Endpoint Groups

Top Endpoints

ICMP Types

Top Interfaces by Traffic

Top Interfaces by Utilization

Top Sources with Interfaces

Traffic Totals

Unclassified Traffic

Class-Based QoS Usage