📄️ Long tail analytics
Long tail analytics analyzes the large number of low-volume traffic items that are individually small but collectively significant. It helps reveal hidden traffic patterns, rare activity, uncommon applications, and behavioral anomalies beyond traditional Top-K or top-talker views.
📄️ TAP vs SPAN port
TAP vs SPAN port compares two methods for network traffic observation. Network TAPs provide passive packet visibility with minimal impact on forwarding behavior, while SPAN ports use switch-based traffic mirroring for monitoring and analysis.
📄️ TCP
TCP, or Transmission Control Protocol, is a connection-oriented transport protocol that provides reliable, ordered, and error-checked data delivery between hosts on IP networks.
📄️ TCP retransmission
TCP retransmission is the automatic resending of unacknowledged TCP segments when transport delivery becomes unstable. Retransmission behavior is an important operational indicator of congestion, packet loss, latency instability, unreliable paths, and degraded application performance across network environments.
📄️ Threat detection
Threat detection is the process of identifying suspicious, malicious, or unauthorized activity by analyzing traffic behavior, telemetry relationships, operational anomalies, and historical activity across networks and systems in order to reconstruct potentially harmful behavior before it causes significant operational impact.
📄️ Threat intelligence
Threat intelligence is information about malicious actors, attack infrastructure, indicators, tactics, and risk patterns used to help organizations detect, investigate, prioritize, and respond to security threats.
📄️ Threshold-based alerting
Threshold-based alerting generates notifications when operational metrics exceed expected limits or deviate from historical behavior. It helps organizations identify congestion, instability, abnormal traffic conditions, service degradation, and emerging operational problems before they cause widespread impact.
📄️ TLS
TLS, or Transport Layer Security, is a cryptographic protocol that encrypts communication between systems to protect confidentiality, integrity, and authentication. Operationally, TLS changes network visibility because encrypted payloads limit direct packet inspection and increase the importance of metadata and behavioral analysis.
📄️ TLS inspection
TLS inspection is the process of decrypting, analyzing, and re-encrypting TLS-encrypted traffic so security and monitoring systems can apply policy, detect threats, and improve visibility into encrypted sessions.
📄️ Top talkers
Top talkers are the hosts, applications, conversations, or network entities responsible for the largest share of network traffic. Top-talker analysis helps operators identify bandwidth consumers, investigate congestion, understand traffic behavior, and support capacity planning.
📄️ Top-K
Top-K is the process of identifying the K highest-ranking items in a dataset based on a selected metric. In network analytics, it is commonly used to find top talkers, applications, destinations, and other high-volume traffic entities.
📄️ Top-K Analyticsᵀ
Top-K Analyticsᵀ is Trisul's proprietary technology for efficiently computing top-N rankings from large-scale flow data using ingestion-time stream summaries instead of expensive query-time scans.
📄️ Trackers
Trackers are monitoring mechanisms that continuously observe specific entities, conditions, or behaviors over time and generate records, alerts, or investigative context when defined criteria are met.
📄️ Traffic direction
Traffic direction describes whether network traffic is inbound, outbound, or bidirectional relative to a device, interface, network segment, or observation point. It provides essential context for understanding how data moves through a network.
📄️ Traffic estimation
Traffic estimation is the process of approximating network traffic volume, utilization, or demand when direct measurement is unavailable, incomplete, sampled, or impractical. It helps operators understand growth trends, forecast capacity requirements, and support planning decisions using available telemetry.
📄️ Traffic investigation
Traffic investigation is the process of analyzing network traffic to determine the cause, scope, and impact of a security incident, performance issue, or unusual network behavior.
📄️ Traffic pattern analysis
Traffic pattern analysis is the process of examining how network traffic behaves over time to identify trends, recurring activity, anomalies, and changes in communication behavior. It helps operators understand normal behavior, establish baselines, and investigate meaningful deviations.
📄️ Traffic prioritization
Traffic prioritization is the process of assigning different levels of service to network traffic so critical applications receive preferential treatment when network resources become constrained.
📄️ Traffic spike analysis
Traffic spike analysis is the process of investigating sudden increases in network traffic to determine their cause, impact, and whether they represent expected activity, operational issues, or security-related events.
📄️ TRAI compliance
TRAI compliance refers to the ability of licensed telecom operators and ISPs in India to maintain the records, traceability, and reporting capabilities required by telecommunications regulations.
📄️ Transit traffic
Transit traffic is traffic that an ISP or network operator forwards between external networks. Transit traffic analysis helps operators understand traffic exchange patterns, optimize routing and peering decisions, manage upstream utilization, and plan network capacity.
📄️ Trend analysis
Trend analysis is the study of how network and performance metrics change over time. It helps operators identify growth patterns, recurring behavior, anomalies, and long-term operational changes.
📄️ Trisul AI (CLI)
Trisul AI (CLI) is an AI-assisted command-line interface that helps operators interact with Trisul Network Analytics using natural language. It simplifies traffic investigations, telemetry exploration, and analytical workflows by reducing the effort required to navigate large datasets.
📄️ Trisul AI (UI)
Trisul AI (UI) is an AI-powered assistant integrated into the Trisul Network Analytics web interface that helps users explore telemetry, investigate network activity, and access analytics through natural-language interactions.
📄️ Tunnel content inspection
Tunnel content inspection is the process of analyzing traffic carried inside network tunnels by decoding encapsulation protocols and examining the underlying communications. It restores visibility into the hosts, applications, and traffic patterns carried within tunneled traffic.