Configuring a Failed Connections Threshold

Track devices experiencing failed, incomplete, or malformed connections. See port scanning, probing, and DoS attacks.

Configure a Network Traffic Analyzer failed connections threshold:

Note: Notification policies are optional for most thresholds. If you do not select a notification policy, no notifications are generated for the threshold, but a dashboard report listing the out of threshold items still appears on the Alert Center Home page.

Add Condition Rules

Select Applied Hosts

Note: Sources sending sampled data are not displayed as a selection option in the Traffic to monitor list because Network Traffic Analyzer cannot determine that traffic has failed on sampled data.

Note: Configure the threshold check interval for a longer time than the sampling interval for thresholds relating to trends, such as percent utilization. Configure it for a time the same as (or similar to) the sampling interval when configuring a threshold for a health check.

Tip: Avoid setting the threshold check interval to a very short time. Aggressive intervals can degrade system performance. In general, setting the threshold check interval to less than five minutes is not advised.

See Also

Failed Connections