Trisul Edges – Streaming Graph Analytics
Trisul Edge adds graph analytics to Trisul. It lets you discover relationships between metric items. This section introduces the Trisul Edge feature and then describes how to use the Trisul User Interface to explore these relationships
📄️ Working with Edges
The entry point into exploring the streaming graph database of Trisul is to select two items
📄️ Multicast GraphX
Multicast GraphX is an interactive visualization tool that helps you explore multicast traffic patterns in your network. It displays a clear and organized layout using D3.js, showing which IPs are sending and receiving multicast data.
📄️ Sankey Drilldown
The Sankey Drill Down App can be downloaded from Trisul Apps. This visualization tool illustrates the split of traffic for various applications, originating from specific routers and interfaces by providing a graphical representation of traffic distribution.
Introducing Trisul Edges
Trisul is a real-time streaming analytics platform. It processes data in a single pass with streaming algorithms, instead of storing data in a search engine such as Elasticsearch or a relational database such as PostgreSQL and querying it on demand. A Trisul Probe captures hundreds of metrics from network traffic. Without Edges, Trisul can relate metrics such as protocol, port and IP address only through the flow they belong to. It can't tell, for example, that a TLS cipher suite was used by a particular IP address, TLS organization or country. The Flow Tagger enriches each flow with tags, but it still uses the flow as the anchor.
Figure: Edge Graph Showing Flow Taggers
Trisul Edges brings graph database features into Trisul. Each entity in Trisul metrics also generates information about related entities. In Graph Database architecture, the central concept is to store “connections” and “graphs of connections” as sets of edges and vertices.
When you enable Trisul Edges, Trisul generates a new type of stream, called an Edge stream, as it processes packets. Streaming algorithms keep this stream to a manageable size. For example, Trisul doesn't store an unbounded graph for high-cardinality relationships.
Vertices and Edges
An Edge connects two Vertices. In Trisul the rules are
- Vertices are keys that belong to a Counter Group or an Alert Group
- Edges are connections between vertices
Consider the following graph.
Figure: Representation of Vertices and Edges in Edge Graph
In Trisul you start traversing graphs from a “root vertex”. In the image shown above we want to check which nodes are connected to the TLS Certificate Authority named “Freebit.Co.Ltd”. The graph then opens up one level to reveal its adjacent vertices. In this case we have vertices from 3 different counter groups Internal Hosts (10.x), External Hosts, and Applications. You can then expand the other nodes to reveal its adjacencies and explore the graph network.
Limits
Trisul uses a memory cap on the number of allowed neighbors per vertex. This prevents an explosion of edges for high-cardinality vertices such as the HTTP protocol. Imagine how many IPs would be neighbors of the HTTP protocol.
The limits currently in effect are :
- Max vertices – unlimited
- Max neighbors per vertex – 1KB / hour. Roughly 100 uniques per hour.