netflow filter improvements
The newer filter capability is appreciated, but would be even better if more complex logic could be applied (AND/OR/NOT for multiple filters) to really focus on specific types of traffic while excluding others. For interfaces, glob matches would be very helpful. For src/dst address match, please allow for prefix matching as well as host matching.
Thanks,
Mark
mnagel
Posted 8 years ago·Last reply 7 years ago
3 comments
Michael Rodrigues
·7 years agoHey @Brandon, @mnagel, we do not currently have these NetFlow enhancements prioritized. I am hearing a decent amount of feedback about NetFlow shortcomings though, so this may get more love later this year, or in 2020.
mnagel
OP7 years agoI see all the crickets have come to this F/R to hang out. This is a pretty important improvement for using NetFlow for incident research. For example, if you find an IP that is doing a lot of traffic while trying to identify a problem and that IP is harmless, I should be able to filter the harmless IP out of my search as I iterate. There is currently no non-API way to do this. If the filters could be complex with AND/OR/NOT and groups, then it would be much simpler to make use of the data for real world investigations.
Similarly, it seems like saved filters are per-user and it would be far more useful if they could be shared across multiple users.