Skip to main content

Web Hosts

Hosts talking HTTP/HTTPS

Counter group​

GUIDTYPEBucke Size (secs)Topper Bucket(Secs):
{EEF95297-0C8D-4673-AD6B-F4BD2345FD69}Filtered60300

Meter list​

IDDESCRIPTIONTOP COUNTBOTTOM COUNTTYPEUNITSDESCRIPTION
0Total500VT_RATE_COUNTERBpsThis meter reports the total bandwidth seen by this host in both the transmit and receive direction, for hosts observed talking HTTP or HTTPS.
1Received100VT_RATE_COUNTERBpsThis meter reports the receive bandwidth of the host, counted when the host's IP address appears in the destination IP field of the packet.
2Transmit100VT_RATE_COUNTERBpsThis meter reports the transmit bandwidth of the host, counted when the host's IP address appears in the source IP field of the packet.
3Total Packets100VT_RATE_COUNTERppsThis meter reports the number of packets seen for this host as either the source IP address or the destination IP address.
4Active conns500VT_RUNNING_COUNTERconnsThis meter reports the number of concurrently active IP flows involving this host at the end of the streaming window. Hosts that top this metric generally have long running flows, such as video, audio, conferencing, or file transfers.
5Attacker alerts200VT_COUNTERalertsThis meter reports the number of IDS or BadFellas alerts where this host was the source IP address of the packet that triggered the alert.
6Homenet200VT_RATE_COUNTERBpsThis meter reports the traffic bandwidth for conversations where the other IP address involved is within the organization's home network.
7External200VT_RATE_COUNTERBpsThis meter reports the traffic bandwidth for conversations where the other IP address involved is outside the home network.
8TCP SYN sent100VT_COUNTERpacketsThis meter reports how many TCP SYN packets were sent with this host's IP address as the source, representing this host acting as the client of a TCP service.
9TCP SYN recv100VT_COUNTERpacketsThis meter reports how many TCP SYN packets were received with this host's IP address as the destination, representing this host acting as the server of a TCP service.
10TCP SYNACK sent100VT_COUNTERpacketsThis meter reports how many TCP SYN plus ACK packets were sent from this host's IP address as the source. A SYN plus ACK packet is the response to a SYN as part of the TCP session setup handshake, so this represents this host acting as the server side of connection setup.
11Blacklist alerts200VT_COUNTERalertsThis meter reports how many alerts were generated involving this IP address as either a source or a destination, sourced from the BadFellas threat intelligence plugin, trisul-badfellas.
12Victim alerts200VT_COUNTERalertsThis meter reports how many alerts were generated with this IP address as the destination address.
13New conns200VT_COUNTERconnsThis meter reports how many new connections were made involving this IP address. Hosts that top this metric generally have short, high frequency connections, such as DNS servers and clients.
14Into Interface200VT_RATE_COUNTERBpsThis meter appears only in a filtered counter group where the parent counter group is Web Hosts and the filter is a NetFlow interface. When used with the NetFlow Interface Tracker, it reports bandwidth involving this IP address as source or destination that is ingressing the interface specified in the interface tracker.
15Outof Interface200VT_RATE_COUNTERBpsThis meter appears only in a filtered counter group where the parent counter group is Web Hosts and the filter is a NetFlow interface. When used with the NetFlow Interface Tracker, it reports bandwidth involving this IP address as source or destination that is egressing the interface specified in the interface tracker.
16Flow Records200VT_COUNTERBpsThis meter reports the number of NetFlow records with this IP address involved as either source or destination.
17Unused Cardinality counter2020VT_GAUGEUniquesThis is a cardinality counter for this counter group. See the cardinality counter groups documentation for how these are populated and used.
18Unused Cardinality counter2020VT_GAUGEUniquesThis is a cardinality counter for this counter group. See the cardinality counter groups documentation for how these are populated and used.