FlowTraq Documentation
Sidebar Prev | Up | Next

14.2. Configuration

14.2.1. Basic Parameters

The FlowTraq NBI Tools share a number of basic configuration parameters in common with the CLI tools; in particular, the -s, -p, -un, -up, -us, -q, -e, -ei, and -ef parameters all work in the same was as they do with the CLI tools. Use these to specify the FlowTraq Server to connect to, the credentials to use to log in, and more. For more information on these parameters, please see Section 13.2, “Retrieving Raw Session Data from the Command Line with ftsq”.

[Tip]NBI Tools and FlowTraq Filters

You can even use -q, -e, -ei, and -ef with standard FlowTraq filters to control what traffic is examined. This allows for very fine grained control over the alerts that are generated, strongly reducing false positives.

14.2.2. Training Options

The FlowTraq NBI Tools all learn network behavioral baselines by first examining a period of historical data. When they are run, they first perform a learning pass over a specified timeframe of historical data (the "training period"), compute baselines, and then begin alerting in real time on the live traffic as it arrives. Specify the training period by using the -tn parameter (to specify a training period relative to now) or using -te/-tl to specify an absolute training period. For more information on these parameters, please see Section 13.2, “Retrieving Raw Session Data from the Command Line with ftsq”.

14.2.3. Logging Options

All of the NBI tools support logging network behavior anomalies to standard out or to syslog. To congifure logging, use the following parameters.

Table 14.1. Logging Parameters

ParameterDescription
-ls Log to stdout (Default: yes UNLESS a loghost is specified via -lh)
-lh LOGHOST Loghost, specify where syslog message are to be sent (Default: syslog is disabled)
-lp PORT Syslog port on the loghost (Default: 512)
-lf FACILITY yslog facility, one of: LOCAL0-LOCAL7. (Default: LOCAL0)
-ll LEVEL Syslog level, one of: EMERG, ALERT, CRIT, ERR, WARNING, NOTICE, INFO, DEBUG. (Default: NOTICE)
-lu MESSAGE User-defined custom message to be added at the end of the syslog message. Enclose in ""-pair.


Prev Up Next
 Home 
  • Contents
  • Search
loading table of contents...
  • What's new in Q3/13
  • Introduction
    • System Overview
    • Support, Training, and Professional Services
      • Technical Support
      • Training and Professional Services
    • Change Log
      • Changes in FlowTraq Q3/13
  • Installation
    • System Requirements
      • Server Hardware Requirements
      • Client Hardware Requirements
      • Platform Requirements
    • Installation
      • Installation Overview
      • Installing or Upgrading FlowTraq Server
        • Preparing For Installation
        • Windows
        • Unix (including Mac OS X)
      • Installing FlowTraq Client
        • Preparing For Installation
        • Windows
        • Mac OS X
        • Unix
  • Initial Configuration
    • Launching FlowTraq Client
    • Logging In
    • Entering a License Key
    • User Administration
      • User Privileges
      • Changing Passwords
      • Adding and Removing Users
      • Granting and Revoking Adminstrative Privileges
      • User Access Control
  • FlowTraq Web Interface and FlowTraq NBI Server
    • Software Prerequisites
    • Installation Overview
    • Detailed Installation Guides
      • OpenSuSE Linux 11 - Installation Guide
      • Ubuntu Linux 10 (Lucid Lynx) - Installation Guide
      • CentOS 6.3 - Installation Guide
    • Access
    • Installation Troubleshooting
      • Error: NBI server not configured.
      • Error: NBI server authentication failed.
      • Error: The FlowTraq Server failed to identify itself.
      • Warning: The NBI server is not authenticated with this FlowTraq server.
  • Configuring Flow Sources
    • Supported Input Formats
    • Configuring NetFlow, cFlow, jFlow, IPFIX, and NSEL
    • Configuring sFlow
    • Using Flow Exporter
    • Troubleshooting Flow Sources
  • The Dashboard
    • Setting Up Your Dashboard
      • Pages
      • Managing Widgets
      • Widget Types
  • Interactive Reports (Workspaces)
    • Workspace Overview
    • Example Workspaces
    • Customizing Workspaces
      • Time Navigation
      • Filtering
        • Building Filters
        • Filter Fields
      • Views
        • Built-in Views
        • Custom Views
        • View Tabs
        • The Connection Graph
      • Workspace Details
    • Saving and Sharing Workspaces
      • Importing and Exporting Workspaces
      • Workspaces Widget
      • Printing and Saving Interactive Reports
  • Scheduled Reports
    • Scheduling Reports
    • Managing and Retrieving Reports
      • Editing, Disabling, and Deleted Scheduled Reports
      • Retrieving Reports
      • Deleting Generated Reports
  • Session Explorer
    • Accessing Session Explorer
    • Using Session Explorer
  • Alerts and Notifications
    • Setting Up Alerts
    • Managing and Retrieving Alerts
      • Editing, Disabling, and Deleting Alerts
      • Viewing Alert Causes
    • Alert Notifications
      • Notifications on the Dashboard
      • Notifications via E-mail
      • Notifications via Syslog Over UDP
      • Retrieving Notifications via the Command Line
  • Server Optimization and Administration
    • Performance Tuning
      • Performance Indicators
        • The Server Status Widget
        • The Flow Rate Widget
      • Performance Controls
        • The Memory Preference Panel
        • The Performance Preference Panel
          • The Session Database
    • Upgrading FlowTraq
      • Automatic Client Upgrades
        • Clearing FlowTraq Client's Library Cache
    • Advanced Administration
      • Starting and Stopping FlowTraq Server
        • Windows
        • Mac OS X
        • Linux
        • BSD
        • Solaris
      • Backing Up the Session Database
      • Clearing the FlowTraq Session Database
      • The FlowTraq Server Configuration File: flowtraq.conf
        • Making Changes to flowtraq.conf
        • Configuration File Format
  • Command Line Interface
    • Overview
    • Retrieving Raw Session Data from the Command Line with ftsq
    • Time Navigation
    • Filter String Syntax
    • Retrieving Statistical Queries from the Command Line with ftstat
    • Managing Users from the Command Line with ftum
    • Session Key Reauthentication
    • Retrieving Alert Notifications via the Command Line
  • The FlowTraq Network Behavioral Intelligence Toolkit
    • Overview
    • Configuration
      • Basic Parameters
      • Training Options
      • Logging Options
    • Usage Notes
      • ftbfg
      • ftdos
      • ftscan
      • fttcv
  • Enabling Flow Export on Common Devices
    • CISCO IOS
  • FlowProxy
    • Installing FlowProxy
    • Starting and Stopping FlowTraq Server
      • Windows
      • Mac OS X
      • Linux
      • BSD
      • Solaris
    • The FlowProxy Configuration File
      • Making Changes to flowproxy.conf
      • Configuration File Format
  • FlowTraq Web API Reference
    • Authentication
      • Request Parameters
      • Response Parameters
      • Example
    • Retrieving Processed FlowTraq Views
      • Request Parameters
      • Response Parameters
      • Example
    • Retrieving Raw NetFlow Sessions
      • Request Parameters
      • Response Parameters
      • Example
  • Flow FAQs
  • Legal Notices
    • END USER LICENSE AGREEMENT FOR FLOWTRAQ
    • Third-Party Software Components
      • Restlet
      • JFreeChart
Search
 

Search Highlighter (On/Off)