Skip to main content

Trisul Traffic Meters

This page describes all the meters available out of the box in Trisul. Installing additional plugins will usually give you even more meters - which will be described in detail by the documentation accompanying each plugin.

It provides the Detailed metrics of each counter group like Total, In, Out, BucketSize, TopperBucketsize, GUID, etc

Goto Customize -> Counters -> View Meters

5 new counter groups in the latest release

HTTP Methods, HTTP Status, Long Fat Tail, Long Thin Tail, and ICMP Types. Over 20 new data points about your network traffic !

Use the table of contents on left to jump to a particular counter group

Special keys

  • SYS:GROUP_TOTALS
    Each counter group has a special key named SYS:GROUP_TOTALS. This meter represents the cumulative total of all keys in a given time interval. You can type use this instead of a key if you want the totals.

Aggregates

Aggregate statistics
CGUID:{393B5EBC-AB41-4387-8F31-8077DB917336}

IDDescriptionTop CountTypeUnits
0Total0VT_RATE_COUNTERBps
1Packets0VT_RATE_COUNTERpps
2Active Sessions0VT_GAUGEsess
3Layer 2 Broadcast0VT_RATE_COUNTERBps
4Layer 2 Multicast0VT_RATE_COUNTERBps
5Layer 2 Unicast0VT_RATE_COUNTERBps
6Layer 2 Broadcast0VT_RATE_COUNTERBps
7Layer 2 Multicast0VT_RATE_COUNTERBps
8Layer 2 Unicast0VT_RATE_COUNTERBps

Special Keys

The following keys are available in this group

KeyDescription
TOTALBWTotal traffic seen
DIR_INCOMINGIncoming traffic - based on defined home network
DIR_OUTGOINGOutgoing traffic - based on defined home network
DIR_INTERNALInternal traffic - when both source and destination IPs in in home network
DIR_TRANSITTransit traffic - when neither source nor destination is in home network

Hosts

Stats for each IP Host
CUID:{4CD742B1-C1CA-4708-BE78-0FCA2EB01A86}

IDDescriptionTop CountTypeUnits
0Total50VT_RATE_COUNTERBps
1Received10VT_RATE_COUNTERBps
2Transmit10VT_RATE_COUNTERBps
3Total0VT_RATE_COUNTERpps
4Active TCP Conns50VT_COUNTERconns
5Attacker alerts10VT_GAUGEalerts
6Homenet20VT_RATE_COUNTERBps
7External20VT_RATE_COUNTERBps
8TCP SYN sent10VT_GAUGEpackets
9TCP SYN recv10VT_GAUGEpackets
10TCP SYNACK sent10VT_GAUGEpackets
11TCP RSTFIN sent0VT_GAUGEpackets
12Victim alerts10VT_GAUGEalerts
13Flows10VT_COUNTERflows

The following groups are derived from Hosts.

  1. Internal Hosts
  2. External Hosts
  3. Web Hosts
  4. Email Hosts
  5. SSH Hosts
  6. Unusual Traffic Hosts

Apps

Application wise traffic
CGUID:{C51B48D4-7876-479E-B0D9-BD9EFF03CE2E}

IDDescriptionTop CountTypeUnits
0Total50VT_RATE_COUNTERBps
1Security Alerts10VT_COUNTERAlerts
2Into Homenet50VT_RATE_COUNTERBps
3Outof Homenet50VT_RATE_COUNTERBps
4Connections50VT_GAUGEConns

Subnets

Stats for configured IP Subnets
CGUID:{429B65AD-CDA4-452E-A852-24D8A3D0FBB3}

IDDescriptionTop CountTypeUnits
0Total bits/sec10VT_RATE_COUNTERBps
1Received bits/sec0VT_RATE_COUNTERBps
2Transmit bits/sec0VT_RATE_COUNTERBps
3Total pkts/sec0VT_RATE_COUNTERpps

Dir Mac

Traffic between two MACs
CGUID:{79F60A94-44BD-4C55-891A-77823D59161B}

IDDescriptionTop CountTypeUnits
0Total10VT_RATE_COUNTERBps
1A->Z0VT_RATE_COUNTERBps
2Z->A0VT_RATE_COUNTERBps

Mac

Traffic per Ethernet MAC
CGUID:{4B09BD22-3B99-40FC-8215-94A430EA0A35}

IDDescriptionTop CountTypeUnits
0Transmit20VT_RATE_COUNTERBps
1Receive20VT_RATE_COUNTERBps

Interfaces

Per interface statistics
CGUID:{8AC478BC-8891-0009-5F31-80774B010086}

IDDescriptionTop CountTypeUnits
0Total10VT_RATE_COUNTERBps
1Packets0VT_RATE_COUNTERpps

LinkLayerStats

Breakdown of activity at link layer
CGUID:{9F5AD3A9-C74D-46D8-A8A8-DCDD773730BA}

IDDescriptionTop CountTypeUnits
0Total bytes/sec10VT_RATE_COUNTERBps
1Total pkts/sec0VT_RATE_COUNTERpps

NetworkLayerStats

Breakdown of activity at network layer
CGUID:{E89BCD56-30AD-40F5-B1C8-8B7683F440BD}

IDDescriptionTypeUnits
0Total bytes/secVT_RATE_COUNTERBps
1Total pkts/secVT_RATE_COUNTERpps
2Active FlowsVT_GAUGEflows
3Total FlowsVT_COUNTERflows

VSAT

Traffic per VSAT
CGUID:{A8776788-B8E3-4108-AD24-0E3927D9364B}

IDDescriptionTop CountTypeUnits
0Total20VT_RATE_COUNTERBps
1Out-Route20VT_RATE_COUNTERBps
2In-Route20VT_RATE_COUNTERBps
3UDP down15VT_RATE_COUNTERBps
4UDP up15VT_RATE_COUNTERBps
5TCP down15VT_RATE_COUNTERBps
6TCP up15VT_RATE_COUNTERBps
7Mcast down15VT_RATE_COUNTERBps
8Mcast up15VT_RATE_COUNTERBps
9Others down15VT_RATE_COUNTERBps
10Others up15VT_RATE_COUNTERBps

VLANStats

Per VLAN Activity Monitor
CGUID:{0EC72E9E-3AD2-43FD-8173-74693EEA08D0}

IDDescriptionTop CountTypeUnits
0Total bytes/sec20VT_RATE_COUNTERBps

HostsIPv6

Stats for each IPv6 Host
CGUID:{6CD742B1-C1CA-4708-BE78-0FCA2EB01A86}

IDDescriptionTop CountTypeUnits
0Total50VT_RATE_COUNTERBps
1Received10VT_RATE_COUNTERBps
2Transmit10VT_RATE_COUNTERBps
3Total0VT_RATE_COUNTERpps
4Active TCP Conns50VT_COUNTERconns
5Attacker alerts10VT_GAUGEalerts
6Homenet20VT_RATE_COUNTERBps
7External20VT_RATE_COUNTERBps
8TCP SYN sent10VT_GAUGEpackets
9TCP SYN recv10VT_GAUGEpackets
10TCP SYNACK sent10VT_GAUGEpackets
11TCP RSTFIN sent0VT_GAUGEpackets
12Victim alerts10VT_GAUGEalerts

Meta Counter Group

Second order stats for counters
CGUID:{4D88CC23-2883-4DEA-A313-A23B60FE8BDA}

IDDescriptionTop CountTypeUnits
0Master Size0VT_GAUGEi
1MRU Size0VT_GAUGEi
2Pending KU Size0VT_GAUGEi
3Flush US0VT_GAUGEi
4Flush Keys0VT_GAUGEi
5New Keys0VT_GAUGEi
6Key Hits0VT_GAUGEi
7Unflushed Keys0VT_GAUGEi
8Heap mem0VT_GAUGEi
9Tail Prunes0VT_GAUGEi
10Hi Water Rej0VT_GAUGEi

Meta Session Group

Second order stats for flow activity
Used to monitor flow setup, teardown, expiry activity in detail.
CGUID:{594606BD-EEB2-4E0B-BAC4-84B7057088C8}

IDDescriptionTop CountTypeUnits
0Master Size0VT_GAUGEi
1MRU Size0VT_GAUGEi
2New0VT_GAUGEi
3Closed0VT_GAUGEi
4Expired0VT_GAUGEi
5Terminated0VT_GAUGEi
6Flushed0VT_GAUGEi
7FlushedActive0VT_GAUGEi
8Key Hits0VT_GAUGEi
9Heap mem0VT_GAUGEi
10Tail Prunes0VT_GAUGEi
11Hi Water Rej0VT_GAUGEi
12After Term0VT_GAUGEi
13Flush USecs0VT_GAUGEi

Special Keys

The following keys are available

KeyDescription
{99A78737-4B41-4387-8F31-8077DB917336}Meters for TCP/UDP flows

Alert Signatures

Individual Alert Signatures
CGUID:{A0FA9464-B496-4A20-A9AB-4D2D09AFF902}

IDDescriptionTop CountTypeUnits
0Total Alerts20VT_GAUGECount

Alert Classes

IDS Alert Classfication
CGUID:{20BC4345-37F0-44D0-ABFF-3BED97363CB1}

IDDescriptionTop CountTypeUnits
0Total Alerts20VT_GAUGECount

FlowGens

Flow generator traffic
CGUID:{2314BB8E-2BCC-4B86-8AA2-677E5554C0FE}

IDDescriptionTop CountTypeUnits
0Total Bytes/sec10VT_RATE_COUNTERBps
1Total Flow Bytes/sec10VT_RATE_COUNTERBps
2Flow Records/sec0VT_RATE_COUNTERRps

FlowIntfs Active

Flow interface traffic
CGUID{C0B04CA7-95FA-44EF-8475-3835F3314761}

IDDescriptionTop CountTypeUnits
0Bytes/sec Recv10VT_RATE_COUNTERBps
1Bytes/sec Xmit10VT_RATE_COUNTERBps

HTTP Hosts

Traffic by HTTP Host Headers
CGUID:{D2AAD7C6-E129-4366-A2AD-A8CB9AA4C2F4}

IDDescriptionTop CountTypeUnits
0Total Traffic50VT_RATE_COUNTERBps

HTTP Content Types

Traffic by HTTP Content Types
CGUID:{C0C9757F-2005-4CC5-BB96-D72F607E6188}

IDDescriptionTop CountTypeUnits
0Total Traffic20VT_RATE_COUNTERBps

TLS CA (Certificate Authority)

Traffic by certificate authority. Trisul looks at the cert chain
and meters root and intermediate CAs separately.

IDDescriptionTop CountTypeUnits
0Intermediate20VT_COUNTERhits
1Root20VT_COUNTERhits

This tells you how many SSL/TLS flows were seen for each CA.

TLS Ciphers

Traffic by TLS Cipher Suite.

IDDescriptionTop CountTypeUnits
0Total Traffic20VT_RATE_COUNTERbps
1Hits20VT_COUNTERhits

TLS Organization

Traffic by TLS Organization, extracted by normalizing the Subject name.

IDDescriptionTop CountTypeUnits
0Total Traffic20VT_RATE_COUNTERbps
1Hits20VT_COUNTERhits

HTTP Methods

Meters HTTP methods (GET/POST/HEAD/OPTIONS etc).

IDDescriptionTop CountTypeUnits
0Total20VT_COUNTERhits

HTTP Status Codes

Meters HTTP Status codes found in responses (OK/Not Found/Not Modified etc)

IDDescriptionTop CountTypeUnits
0Total Traffic20VT_COUNTERhits

ICMP Types

ICMP Type + Code metering.

IDDescriptionTop CountTypeUnits
0Bytes20VT_RATE_COUNTERbps
1Packets20VT_RATE_COUNTERpps

Long Fat Tail Hosts

Needs Badfellas

Meters hosts that are not in the top 10% of global popularity lists.

IDDescriptionTop CountTypeUnits
0Total Traffic20VT_RATE_COUNTERbps

Long Thin Tail Hosts

Needs Badfellas

Meters hosts that are not in the global popularity lists.

IDDescriptionTop CountTypeUnits
0Total Traffic20VT_RATE_COUNTERbps