Trisul Network Security Monitoring (NSM) Guide
Welcome to the Trisul Network Security Monitoring (NSM) Guide.
Trisul NSM is designed for comprehensive network security monitoring, traffic analysis, threat detection, and packet-level visibility. It combines flow monitoring, full packet capture (PCAP), IDS alert correlation (Suricata/Snort), network behavioral analysis (NBAD), and protocol extraction in a unified platform.
With Trisul NSM, you can:
- Monitor and analyze network traffic in real time and retrospectively
- Detect security incidents, intrusions, and anomalous network behavior
- Correlate IDS alerts with raw packet captures and flow history
- Track top talkers, applications, conversation flows, and host endpoints
- Perform deep protocol inspection (DNS, HTTP, SSL/TLS, and more)
- Investigate historical traffic without data loss
- Automate alerts and generate compliance and security reports
Before you begin
If you have not installed Trisul yet, start with the installation guide.
During installation, select Network Security Monitoring (NSM) as the Product Mode. This configures Trisul for comprehensive security telemetry and packet analysis.
Install Trisul and select NSM mode
Once Trisul is installed and you have logged in to the Web UI, return to this guide to learn how to use the NSM interface.
The screens and menus described in this guide are available when Trisul is configured in NSM mode. If you selected a different Product Mode during installation, your Web UI may have a different menu structure.
What you will find in this guide
The NSM Web UI is organized into ten main menu categories. Each category helps you perform a different type of network monitoring or security analysis:
🗃️ Dashboards
Use dashboards for a quick view of what is happening in your network. You can monitor current traffic, active hosts, applications, alerts, security information, sessions, and other frequently used network metrics.
🗃️ Retro
Use Retro when you want to look back at network activity that has already happened. It lets you inspect historical counters and analyze traffic for a specific period in the past.
🗃️ Tools
Use the Tools section when you need to investigate traffic in more detail. It includes flow exploration, historical trends, IP flow exports, usage charts, flow trackers, taggers, and edge connection graphs.
🗃️ Security
Use the Security section for access to monthly security summaries and unified alert views.
🗃️ Netflow
Use the Netflow section to understand where your flow data is coming from and how traffic is distributed across your network devices and interfaces. You can view NetFlow sources, exporters, routers, interfaces, and interface-level traffic details.
🗃️ Resources
Use the Resources section for deep protocol analysis, DNS, URL, and certificate inspection.
🗃️ Alerts
Use Alerts to identify traffic conditions that require attention. You can configure Threshold Crossing Alerts (TCAs), flow tracking alerts, blacklist matching, dynamic threshold bands, and view alert activity.
🗃️ Reports
Use Reports when you need to turn network traffic data into reports that can be reviewed or shared. This section includes standard reports, scheduled recurring reports, and email delivery settings.
🗃️ Customize
Use Customize to adjust how the NSM Web UI behaves and looks. You can personalize dashboard layouts, real-time parameters, and HTTP/HTTPS traffic classification rules.
🗃️ NBAD
Use Network Behavioral Anomaly Detection (NBAD) for tracking protocol anomalies, Layer 7 metrics, DDoS, and MITRE ATT&CK telemetry.