Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20396

Re: NTA Newbie

$
0
0

Hi Pat,

NetFlow data is very much like a phone bill. You see all the calls, how much they cost and a total at the end. However, you see no reference as to what was discussed on the calls and this is like flow data.

 

To get the level of visibility that you need you need to look inside the packet payloads to extract things like file names and for that you need to deploy deep packet inspection. You can see an example of this in action at this link. You can see the names of files which are moving to and from Windows file shares. Similar reports can be setup for users accessing web resources.

 

Darragh


Viewing all articles
Browse latest Browse all 20396

Trending Articles