SlideShare une entreprise Scribd logo
1  sur  34
Emulex Confidential - © 2013 Emulex Corporation
EndaceVision with Packet Decodes
An Introduction to Endace Packets
Jim MacLeod – Senior Product Manager, Emulex
2 Emulex Confidential - © 2013 Emulex Corporation
Introduction
Jim MacLeod
– Senior Product Manager, Emulex
– 15 years experience in monitoring
– Product Manager for EndaceVision
Endace
– Emulex product line
– World leader in network recording
– 10 years selling network visibility
3 Emulex Confidential - © 2013 Emulex Corporation
Changing Nature of Networks
Rapid shift to 10GbE
– 40 and 100GbE adoption coming
Increasing complexity
– Consolidation
– Virtualization
Greater reliance on network
– Virtual Desktop
– Unified Communications
More compliance & regulation
– Business and customer data
– Scope of data at rest
Lower tolerance to downtime…
– Cost measured in millions of dollars
4 Emulex Confidential - © 2013 Emulex Corporation
Who’d Want To Be An Analyst?
Insane pressure to resolve
complex issues fast
More events than time
– ‘Triage’ strategy
Lack of immediate data
– Still living in ‘HHA’ mode
Tool paralysis
– Too many
– Too complex
– Too slow
#Fail.
5 Emulex Confidential - © 2013 Emulex Corporation
Sharkbites - the Problem with Wireshark…
Wireshark remains the go-to tool for
most analysts and security engineers
Tool fails under 10GbE load
– 14,000,000 pps on loaded 10GbE link
Faster network, slower analysis
– 5 minutes to open 5GB file on Core i5
– 5 minutes for each filter
Troubleshooting requires accurate data
– Recording at 10Gbps is challenging
– Trace files need to be moved around
Real compliance / security concerns
6 Emulex Confidential - © 2013 Emulex Corporation
10GbE Troubleshooting Best Practice
Pervasive network recording
– 100% accurate capture to disk
Effective traffic search
– Trace file consolidation
Event driven trace extraction
High-level trace visualization
– Layer 7 awareness is vital
Effective drill-in to precise
packets of interest
On-appliance protocol decoder
– Filters in seconds, not minutes
Easy trace file export for deep-
dive in Wireshark
7 Emulex Confidential - © 2013 Emulex Corporation
8 Emulex Confidential - © 2013 Emulex Corporation
9 Emulex Confidential - © 2013 Emulex Corporation
10 Emulex Confidential - © 2013 Emulex Corporation
11 Emulex Confidential - © 2013 Emulex Corporation
12 Emulex Confidential - © 2013 Emulex Corporation
13 Emulex Confidential - © 2013 Emulex Corporation
14 Emulex Confidential - © 2013 Emulex Corporation
15 Emulex Confidential - © 2013 Emulex Corporation
16 Emulex Confidential - © 2013 Emulex Corporation
17 Emulex Confidential - © 2013 Emulex Corporation
18 Emulex Confidential - © 2013 Emulex Corporation
19 Emulex Confidential - © 2013 Emulex Corporation
20 Emulex Confidential - © 2013 Emulex Corporation
21 Emulex Confidential - © 2013 Emulex Corporation
22 Emulex Confidential - © 2013 Emulex Corporation
23 Emulex Confidential - © 2013 Emulex Corporation
24 Emulex Confidential - © 2013 Emulex Corporation
25 Emulex Confidential - © 2013 Emulex Corporation
26 Emulex Confidential - © 2013 Emulex Corporation
27 Emulex Confidential - © 2013 Emulex Corporation
28 Emulex Confidential - © 2013 Emulex Corporation
29 Emulex Confidential - © 2013 Emulex Corporation
30 Emulex Confidential - © 2013 Emulex Corporation
31 Emulex Confidential - © 2013 Emulex Corporation
A New Recording Paradigm
EndaceProbe next generation sniffer
100% accurate traffic recording
– Real 10 Gbps performance
Up to 64 TB of local storage
– Extensible via sledding or SAN
Full flow-based traffic indexing
– Including application classification
Open and flexible
– Endace Application Dock
– Programmable RESTful API
EndaceVision / Endace Packets
32 Emulex Confidential - © 2013 Emulex Corporation
Total Datacentre Visibility
33 Emulex Confidential - © 2013 Emulex Corporation
Conclusion
Troubleshooting in a 10GbE world
requires 10GbE capable tools
Wireshark needs support to remain
relevant in high-speed environment
EndaceVision & Endace Packets
solve the scalability challenge
100% accurate recording is
mandatory input
– Dedicated purpose built hardware
Long live Wireshark!
34 Emulex Confidential - © 2013 Emulex Corporation
Thank you.
jim.macleod@emulex.com
www.emulex.com

Contenu connexe

Tendances

Здоровье важнее - Fortinet решения для удаленных сотрудников
Здоровье важнее - Fortinet решения для удаленных сотрудниковЗдоровье важнее - Fortinet решения для удаленных сотрудников
Здоровье важнее - Fortinet решения для удаленных сотрудниковMUK Extreme
 
Ensemble Director
Ensemble DirectorEnsemble Director
Ensemble DirectorADVA
 
Cloud managed secure wi fi
Cloud managed secure wi fiCloud managed secure wi fi
Cloud managed secure wi figruzabb
 
FSP 150 ProVMe (P2.4): The Easy Route to Edge NFV
FSP 150 ProVMe (P2.4): The Easy Route to Edge NFVFSP 150 ProVMe (P2.4): The Easy Route to Edge NFV
FSP 150 ProVMe (P2.4): The Easy Route to Edge NFVADVA
 
ADVA Disaggregated NOS
ADVA Disaggregated NOSADVA Disaggregated NOS
ADVA Disaggregated NOSDan Dovolsky
 
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFVRevolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFVPLUMgrid
 
Verizon Selects Ensemble Connector to Deliver VNS uCPE
Verizon Selects Ensemble Connector to Deliver VNS uCPEVerizon Selects Ensemble Connector to Deliver VNS uCPE
Verizon Selects Ensemble Connector to Deliver VNS uCPEADVA
 
Introducing the ADVA FSP 150-GE110 Pro Series
Introducing the ADVA FSP 150-GE110 Pro SeriesIntroducing the ADVA FSP 150-GE110 Pro Series
Introducing the ADVA FSP 150-GE110 Pro SeriesADVA
 
White Box Optics: Will It Kill or Encourage Innovation?
White Box Optics: Will It Kill or Encourage Innovation?White Box Optics: Will It Kill or Encourage Innovation?
White Box Optics: Will It Kill or Encourage Innovation?ADVA
 
Introducing Ensemble Simulator – ADVA’s virtual networking environment
Introducing Ensemble Simulator – ADVA’s virtual networking environmentIntroducing Ensemble Simulator – ADVA’s virtual networking environment
Introducing Ensemble Simulator – ADVA’s virtual networking environmentADVA
 
Securing the LTE Core: the Road to NFV
Securing the LTE Core:  the Road to NFVSecuring the LTE Core:  the Road to NFV
Securing the LTE Core: the Road to NFVMary McEvoy Carroll
 
Synchronization in Cable Networks
Synchronization in Cable NetworksSynchronization in Cable Networks
Synchronization in Cable NetworksADVA
 
Ditek PVPIP Data Sheet
Ditek PVPIP Data SheetDitek PVPIP Data Sheet
Ditek PVPIP Data SheetJMAC Supply
 
5G: Why Wait? - 5G Observatory 2016
5G: Why Wait? - 5G Observatory 20165G: Why Wait? - 5G Observatory 2016
5G: Why Wait? - 5G Observatory 2016Daniel Sproats
 
ADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber Assurance
ADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber AssuranceADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber Assurance
ADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber AssuranceADVA
 
Announcing Ensemble SmartWAN: Optimized secure networking solution
Announcing Ensemble SmartWAN: Optimized secure networking solutionAnnouncing Ensemble SmartWAN: Optimized secure networking solution
Announcing Ensemble SmartWAN: Optimized secure networking solutionADVA
 
Introducing the ADVA MicroMux™
Introducing the ADVA MicroMux™Introducing the ADVA MicroMux™
Introducing the ADVA MicroMux™ADVA
 
Cisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful TechnologyCisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful TechnologyCisco Canada
 
Deploying Virtualized Services Over Legacy Networks
Deploying Virtualized Services Over Legacy NetworksDeploying Virtualized Services Over Legacy Networks
Deploying Virtualized Services Over Legacy NetworksDaniel Sproats
 

Tendances (20)

Здоровье важнее - Fortinet решения для удаленных сотрудников
Здоровье важнее - Fortinet решения для удаленных сотрудниковЗдоровье важнее - Fortinet решения для удаленных сотрудников
Здоровье важнее - Fortinet решения для удаленных сотрудников
 
Ensemble Director
Ensemble DirectorEnsemble Director
Ensemble Director
 
Cloud managed secure wi fi
Cloud managed secure wi fiCloud managed secure wi fi
Cloud managed secure wi fi
 
FSP 150 ProVMe (P2.4): The Easy Route to Edge NFV
FSP 150 ProVMe (P2.4): The Easy Route to Edge NFVFSP 150 ProVMe (P2.4): The Easy Route to Edge NFV
FSP 150 ProVMe (P2.4): The Easy Route to Edge NFV
 
ADVA Disaggregated NOS
ADVA Disaggregated NOSADVA Disaggregated NOS
ADVA Disaggregated NOS
 
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFVRevolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
Revolutionizing IT and Telecom Industry with OpenStack, SDN and NFV
 
Verizon Selects Ensemble Connector to Deliver VNS uCPE
Verizon Selects Ensemble Connector to Deliver VNS uCPEVerizon Selects Ensemble Connector to Deliver VNS uCPE
Verizon Selects Ensemble Connector to Deliver VNS uCPE
 
Introducing the ADVA FSP 150-GE110 Pro Series
Introducing the ADVA FSP 150-GE110 Pro SeriesIntroducing the ADVA FSP 150-GE110 Pro Series
Introducing the ADVA FSP 150-GE110 Pro Series
 
White Box Optics: Will It Kill or Encourage Innovation?
White Box Optics: Will It Kill or Encourage Innovation?White Box Optics: Will It Kill or Encourage Innovation?
White Box Optics: Will It Kill or Encourage Innovation?
 
Introducing Ensemble Simulator – ADVA’s virtual networking environment
Introducing Ensemble Simulator – ADVA’s virtual networking environmentIntroducing Ensemble Simulator – ADVA’s virtual networking environment
Introducing Ensemble Simulator – ADVA’s virtual networking environment
 
Securing the LTE Core: the Road to NFV
Securing the LTE Core:  the Road to NFVSecuring the LTE Core:  the Road to NFV
Securing the LTE Core: the Road to NFV
 
Synchronization in Cable Networks
Synchronization in Cable NetworksSynchronization in Cable Networks
Synchronization in Cable Networks
 
Ditek PVPIP Data Sheet
Ditek PVPIP Data SheetDitek PVPIP Data Sheet
Ditek PVPIP Data Sheet
 
5G: Why Wait? - 5G Observatory 2016
5G: Why Wait? - 5G Observatory 20165G: Why Wait? - 5G Observatory 2016
5G: Why Wait? - 5G Observatory 2016
 
ADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber Assurance
ADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber AssuranceADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber Assurance
ADVA ALM: Advanced Link Monitoring Technology for Ultimate Fiber Assurance
 
Announcing Ensemble SmartWAN: Optimized secure networking solution
Announcing Ensemble SmartWAN: Optimized secure networking solutionAnnouncing Ensemble SmartWAN: Optimized secure networking solution
Announcing Ensemble SmartWAN: Optimized secure networking solution
 
Introducing the ADVA MicroMux™
Introducing the ADVA MicroMux™Introducing the ADVA MicroMux™
Introducing the ADVA MicroMux™
 
Cisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful TechnologyCisco Meraki - Simplifying Powerful Technology
Cisco Meraki - Simplifying Powerful Technology
 
SDN-architecture
SDN-architectureSDN-architecture
SDN-architecture
 
Deploying Virtualized Services Over Legacy Networks
Deploying Virtualized Services Over Legacy NetworksDeploying Virtualized Services Over Legacy Networks
Deploying Virtualized Services Over Legacy Networks
 

Similaire à Introducing Endace Packets - EndaceVision™ with Protocol Decodes

Network Forensics for Splunk, an Emulex presentation
Network Forensics for Splunk, an Emulex presentationNetwork Forensics for Splunk, an Emulex presentation
Network Forensics for Splunk, an Emulex presentationEmulex Corporation
 
An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...
An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...
An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...Emulex Corporation
 
Integrating and Optimizing Suricata with FastStack™ Sniffer10G™
Integrating and Optimizing Suricata with FastStack™ Sniffer10G™Integrating and Optimizing Suricata with FastStack™ Sniffer10G™
Integrating and Optimizing Suricata with FastStack™ Sniffer10G™Emulex Corporation
 
EMC isilon for -media-and-entertainment-sales-deck
EMC isilon for -media-and-entertainment-sales-deckEMC isilon for -media-and-entertainment-sales-deck
EMC isilon for -media-and-entertainment-sales-decksolarisyougood
 
Cloud Models, Considerations, & Adoption Techniques
Cloud Models, Considerations, & Adoption TechniquesCloud Models, Considerations, & Adoption Techniques
Cloud Models, Considerations, & Adoption TechniquesEMC
 
Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0
Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0
Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0xKinAnx
 
Simplify Data Management and Go Green with Supermicro & Qumulo
Simplify Data Management and Go Green with Supermicro & QumuloSimplify Data Management and Go Green with Supermicro & Qumulo
Simplify Data Management and Go Green with Supermicro & QumuloRebekah Rodriguez
 
Scaling small cell deployment - Why current tools are inadequate
Scaling small cell deployment - Why current tools are inadequateScaling small cell deployment - Why current tools are inadequate
Scaling small cell deployment - Why current tools are inadequateDavid Chambers
 
Webcast: Reduce latency, improve analytics and maximize asset utilization in ...
Webcast: Reduce latency, improve analytics and maximize asset utilization in ...Webcast: Reduce latency, improve analytics and maximize asset utilization in ...
Webcast: Reduce latency, improve analytics and maximize asset utilization in ...Emulex Corporation
 
Transforming Mission Critical Applications
Transforming Mission Critical ApplicationsTransforming Mission Critical Applications
Transforming Mission Critical ApplicationsCenk Ersoy
 
Pro sphere customer technical
Pro sphere customer technicalPro sphere customer technical
Pro sphere customer technicalsolarisyougood
 
Emc vi pr global data services
Emc vi pr global data servicesEmc vi pr global data services
Emc vi pr global data servicessolarisyougood
 
Delivering First Class performance and Availability for Virtualized Tier 1 Apps
Delivering First Class performance and Availability for Virtualized Tier 1 Apps Delivering First Class performance and Availability for Virtualized Tier 1 Apps
Delivering First Class performance and Availability for Virtualized Tier 1 Apps DataCore Software
 
INDUSTRY-LEADING TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUD
INDUSTRY-LEADING  TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUDINDUSTRY-LEADING  TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUD
INDUSTRY-LEADING TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUDEMC
 
Pcdvpcu en ex9200-customer-presentation-1
Pcdvpcu en ex9200-customer-presentation-1Pcdvpcu en ex9200-customer-presentation-1
Pcdvpcu en ex9200-customer-presentation-1He Hariyadi
 
How Security can be stronger than a Firewall: 13 different ways breaking thro...
How Security can be stronger than a Firewall: 13 different ways breaking thro...How Security can be stronger than a Firewall: 13 different ways breaking thro...
How Security can be stronger than a Firewall: 13 different ways breaking thro...Community Protection Forum
 
Neutron VEB Plugin
Neutron VEB PluginNeutron VEB Plugin
Neutron VEB PluginBIM
 
Emc vi pr software defined storage
Emc vi pr software defined storageEmc vi pr software defined storage
Emc vi pr software defined storagesolarisyougood
 

Similaire à Introducing Endace Packets - EndaceVision™ with Protocol Decodes (20)

Network Forensics for Splunk, an Emulex presentation
Network Forensics for Splunk, an Emulex presentationNetwork Forensics for Splunk, an Emulex presentation
Network Forensics for Splunk, an Emulex presentation
 
An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...
An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...
An Introduction to the Emulex Network Xceleration Solution – FastStack™ Sniff...
 
Integrating and Optimizing Suricata with FastStack™ Sniffer10G™
Integrating and Optimizing Suricata with FastStack™ Sniffer10G™Integrating and Optimizing Suricata with FastStack™ Sniffer10G™
Integrating and Optimizing Suricata with FastStack™ Sniffer10G™
 
EMC isilon for -media-and-entertainment-sales-deck
EMC isilon for -media-and-entertainment-sales-deckEMC isilon for -media-and-entertainment-sales-deck
EMC isilon for -media-and-entertainment-sales-deck
 
Cloud Models, Considerations, & Adoption Techniques
Cloud Models, Considerations, & Adoption TechniquesCloud Models, Considerations, & Adoption Techniques
Cloud Models, Considerations, & Adoption Techniques
 
Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0
Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0
Emc vspex customer_presentation_euc_citrix_xen_desktop5.6_2.0
 
Simplify Data Management and Go Green with Supermicro & Qumulo
Simplify Data Management and Go Green with Supermicro & QumuloSimplify Data Management and Go Green with Supermicro & Qumulo
Simplify Data Management and Go Green with Supermicro & Qumulo
 
Scaling small cell deployment - Why current tools are inadequate
Scaling small cell deployment - Why current tools are inadequateScaling small cell deployment - Why current tools are inadequate
Scaling small cell deployment - Why current tools are inadequate
 
Datacenter 2014: Commscope - Arne Keller
Datacenter 2014: Commscope - Arne KellerDatacenter 2014: Commscope - Arne Keller
Datacenter 2014: Commscope - Arne Keller
 
Webcast: Reduce latency, improve analytics and maximize asset utilization in ...
Webcast: Reduce latency, improve analytics and maximize asset utilization in ...Webcast: Reduce latency, improve analytics and maximize asset utilization in ...
Webcast: Reduce latency, improve analytics and maximize asset utilization in ...
 
Transforming Mission Critical Applications
Transforming Mission Critical ApplicationsTransforming Mission Critical Applications
Transforming Mission Critical Applications
 
EMC VNX
EMC VNXEMC VNX
EMC VNX
 
Pro sphere customer technical
Pro sphere customer technicalPro sphere customer technical
Pro sphere customer technical
 
Emc vi pr global data services
Emc vi pr global data servicesEmc vi pr global data services
Emc vi pr global data services
 
Delivering First Class performance and Availability for Virtualized Tier 1 Apps
Delivering First Class performance and Availability for Virtualized Tier 1 Apps Delivering First Class performance and Availability for Virtualized Tier 1 Apps
Delivering First Class performance and Availability for Virtualized Tier 1 Apps
 
INDUSTRY-LEADING TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUD
INDUSTRY-LEADING  TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUDINDUSTRY-LEADING  TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUD
INDUSTRY-LEADING TECHNOLOGY FOR LONG TERM RETENTION OF BACKUPS IN THE CLOUD
 
Pcdvpcu en ex9200-customer-presentation-1
Pcdvpcu en ex9200-customer-presentation-1Pcdvpcu en ex9200-customer-presentation-1
Pcdvpcu en ex9200-customer-presentation-1
 
How Security can be stronger than a Firewall: 13 different ways breaking thro...
How Security can be stronger than a Firewall: 13 different ways breaking thro...How Security can be stronger than a Firewall: 13 different ways breaking thro...
How Security can be stronger than a Firewall: 13 different ways breaking thro...
 
Neutron VEB Plugin
Neutron VEB PluginNeutron VEB Plugin
Neutron VEB Plugin
 
Emc vi pr software defined storage
Emc vi pr software defined storageEmc vi pr software defined storage
Emc vi pr software defined storage
 

Plus de Emulex Corporation

Acronym Soup – NFV, SDN, OVN and VNF
Acronym Soup – NFV, SDN, OVN and VNFAcronym Soup – NFV, SDN, OVN and VNF
Acronym Soup – NFV, SDN, OVN and VNFEmulex Corporation
 
Improving Incident Response: Building a More Efficient IT Infrastructure
Improving Incident Response: Building a More Efficient IT InfrastructureImproving Incident Response: Building a More Efficient IT Infrastructure
Improving Incident Response: Building a More Efficient IT InfrastructureEmulex Corporation
 
Using NetFlow to Streamline Security Analysis and Response to Cyber Threats
Using NetFlow to Streamline Security Analysis and Response to Cyber ThreatsUsing NetFlow to Streamline Security Analysis and Response to Cyber Threats
Using NetFlow to Streamline Security Analysis and Response to Cyber ThreatsEmulex Corporation
 
Using NetFlow to Improve Network Visibility and Application Performance
Using NetFlow to Improve Network Visibility and Application PerformanceUsing NetFlow to Improve Network Visibility and Application Performance
Using NetFlow to Improve Network Visibility and Application PerformanceEmulex Corporation
 
Using Network Recording and Search to Improve IT Service Delivery
Using Network Recording and Search to Improve IT Service DeliveryUsing Network Recording and Search to Improve IT Service Delivery
Using Network Recording and Search to Improve IT Service DeliveryEmulex Corporation
 
Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...
Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...
Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...Emulex Corporation
 
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network TrafficTap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network TrafficEmulex Corporation
 
First Look Webcast: OneCore Storage SDK 3.6 Roll-out and Walkthrough
First Look Webcast: OneCore Storage SDK 3.6 Roll-out and WalkthroughFirst Look Webcast: OneCore Storage SDK 3.6 Roll-out and Walkthrough
First Look Webcast: OneCore Storage SDK 3.6 Roll-out and WalkthroughEmulex Corporation
 
Why I/O is Strategic for Convergence - with 451 Research
Why I/O is Strategic for Convergence - with 451 ResearchWhy I/O is Strategic for Convergence - with 451 Research
Why I/O is Strategic for Convergence - with 451 ResearchEmulex Corporation
 
Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data
Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data
Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data Emulex Corporation
 
Emulex and IDC Present Why I/O is Strategic for the Cloud
Emulex and IDC Present Why I/O is Strategic for the Cloud Emulex and IDC Present Why I/O is Strategic for the Cloud
Emulex and IDC Present Why I/O is Strategic for the Cloud Emulex Corporation
 
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...Emulex Corporation
 
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...Emulex Corporation
 
Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...
Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...
Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...Emulex Corporation
 
Introducing OneCommand Vision 3.0, I/O management that gives your application...
Introducing OneCommand Vision 3.0, I/O management that gives your application...Introducing OneCommand Vision 3.0, I/O management that gives your application...
Introducing OneCommand Vision 3.0, I/O management that gives your application...Emulex Corporation
 
Emulex Presents Why I/O is Strategic Global Survey Results
Emulex Presents Why I/O is Strategic Global Survey ResultsEmulex Presents Why I/O is Strategic Global Survey Results
Emulex Presents Why I/O is Strategic Global Survey ResultsEmulex Corporation
 
Optimizing Performance of your Oracle Database using 8Gb Fibre Channel
Optimizing Performance of your Oracle Database using 8Gb Fibre ChannelOptimizing Performance of your Oracle Database using 8Gb Fibre Channel
Optimizing Performance of your Oracle Database using 8Gb Fibre ChannelEmulex Corporation
 
How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...
How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...
How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...Emulex Corporation
 

Plus de Emulex Corporation (20)

Acronym Soup – NFV, SDN, OVN and VNF
Acronym Soup – NFV, SDN, OVN and VNFAcronym Soup – NFV, SDN, OVN and VNF
Acronym Soup – NFV, SDN, OVN and VNF
 
Improving Incident Response: Building a More Efficient IT Infrastructure
Improving Incident Response: Building a More Efficient IT InfrastructureImproving Incident Response: Building a More Efficient IT Infrastructure
Improving Incident Response: Building a More Efficient IT Infrastructure
 
SC Magazine eSymposium: SIEM
SC Magazine eSymposium: SIEMSC Magazine eSymposium: SIEM
SC Magazine eSymposium: SIEM
 
Using NetFlow to Streamline Security Analysis and Response to Cyber Threats
Using NetFlow to Streamline Security Analysis and Response to Cyber ThreatsUsing NetFlow to Streamline Security Analysis and Response to Cyber Threats
Using NetFlow to Streamline Security Analysis and Response to Cyber Threats
 
Using NetFlow to Improve Network Visibility and Application Performance
Using NetFlow to Improve Network Visibility and Application PerformanceUsing NetFlow to Improve Network Visibility and Application Performance
Using NetFlow to Improve Network Visibility and Application Performance
 
The Great IT Migration
The Great IT MigrationThe Great IT Migration
The Great IT Migration
 
Using Network Recording and Search to Improve IT Service Delivery
Using Network Recording and Search to Improve IT Service DeliveryUsing Network Recording and Search to Improve IT Service Delivery
Using Network Recording and Search to Improve IT Service Delivery
 
Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...
Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...
Linked in Twitter Facebook Google+ Email Embed Share Flash Across Virtualized...
 
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network TrafficTap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
Tap DANZing - Arista Networks Redefining the Cost of Accessing Network Traffic
 
First Look Webcast: OneCore Storage SDK 3.6 Roll-out and Walkthrough
First Look Webcast: OneCore Storage SDK 3.6 Roll-out and WalkthroughFirst Look Webcast: OneCore Storage SDK 3.6 Roll-out and Walkthrough
First Look Webcast: OneCore Storage SDK 3.6 Roll-out and Walkthrough
 
Why I/O is Strategic for Convergence - with 451 Research
Why I/O is Strategic for Convergence - with 451 ResearchWhy I/O is Strategic for Convergence - with 451 Research
Why I/O is Strategic for Convergence - with 451 Research
 
Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data
Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data
Emulex and the Evaluator Group Present Why I/O is Strategic for Big Data
 
Emulex and IDC Present Why I/O is Strategic for the Cloud
Emulex and IDC Present Why I/O is Strategic for the Cloud Emulex and IDC Present Why I/O is Strategic for the Cloud
Emulex and IDC Present Why I/O is Strategic for the Cloud
 
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
 
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
Get Better I/O Performance in VMware vSphere 5.1 Environments with Emulex 16G...
 
Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...
Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...
Emulex and Enterprise Strategy Group Present Why I/O is Strategic for Virtual...
 
Introducing OneCommand Vision 3.0, I/O management that gives your application...
Introducing OneCommand Vision 3.0, I/O management that gives your application...Introducing OneCommand Vision 3.0, I/O management that gives your application...
Introducing OneCommand Vision 3.0, I/O management that gives your application...
 
Emulex Presents Why I/O is Strategic Global Survey Results
Emulex Presents Why I/O is Strategic Global Survey ResultsEmulex Presents Why I/O is Strategic Global Survey Results
Emulex Presents Why I/O is Strategic Global Survey Results
 
Optimizing Performance of your Oracle Database using 8Gb Fibre Channel
Optimizing Performance of your Oracle Database using 8Gb Fibre ChannelOptimizing Performance of your Oracle Database using 8Gb Fibre Channel
Optimizing Performance of your Oracle Database using 8Gb Fibre Channel
 
How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...
How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...
How to Increase Performance and Virtualization Efficiency with Emulex 16Gb FC...
 

Dernier

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Principled Technologies
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 

Dernier (20)

The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 

Introducing Endace Packets - EndaceVision™ with Protocol Decodes

  • 1. Emulex Confidential - © 2013 Emulex Corporation EndaceVision with Packet Decodes An Introduction to Endace Packets Jim MacLeod – Senior Product Manager, Emulex
  • 2. 2 Emulex Confidential - © 2013 Emulex Corporation Introduction Jim MacLeod – Senior Product Manager, Emulex – 15 years experience in monitoring – Product Manager for EndaceVision Endace – Emulex product line – World leader in network recording – 10 years selling network visibility
  • 3. 3 Emulex Confidential - © 2013 Emulex Corporation Changing Nature of Networks Rapid shift to 10GbE – 40 and 100GbE adoption coming Increasing complexity – Consolidation – Virtualization Greater reliance on network – Virtual Desktop – Unified Communications More compliance & regulation – Business and customer data – Scope of data at rest Lower tolerance to downtime… – Cost measured in millions of dollars
  • 4. 4 Emulex Confidential - © 2013 Emulex Corporation Who’d Want To Be An Analyst? Insane pressure to resolve complex issues fast More events than time – ‘Triage’ strategy Lack of immediate data – Still living in ‘HHA’ mode Tool paralysis – Too many – Too complex – Too slow #Fail.
  • 5. 5 Emulex Confidential - © 2013 Emulex Corporation Sharkbites - the Problem with Wireshark… Wireshark remains the go-to tool for most analysts and security engineers Tool fails under 10GbE load – 14,000,000 pps on loaded 10GbE link Faster network, slower analysis – 5 minutes to open 5GB file on Core i5 – 5 minutes for each filter Troubleshooting requires accurate data – Recording at 10Gbps is challenging – Trace files need to be moved around Real compliance / security concerns
  • 6. 6 Emulex Confidential - © 2013 Emulex Corporation 10GbE Troubleshooting Best Practice Pervasive network recording – 100% accurate capture to disk Effective traffic search – Trace file consolidation Event driven trace extraction High-level trace visualization – Layer 7 awareness is vital Effective drill-in to precise packets of interest On-appliance protocol decoder – Filters in seconds, not minutes Easy trace file export for deep- dive in Wireshark
  • 7. 7 Emulex Confidential - © 2013 Emulex Corporation
  • 8. 8 Emulex Confidential - © 2013 Emulex Corporation
  • 9. 9 Emulex Confidential - © 2013 Emulex Corporation
  • 10. 10 Emulex Confidential - © 2013 Emulex Corporation
  • 11. 11 Emulex Confidential - © 2013 Emulex Corporation
  • 12. 12 Emulex Confidential - © 2013 Emulex Corporation
  • 13. 13 Emulex Confidential - © 2013 Emulex Corporation
  • 14. 14 Emulex Confidential - © 2013 Emulex Corporation
  • 15. 15 Emulex Confidential - © 2013 Emulex Corporation
  • 16. 16 Emulex Confidential - © 2013 Emulex Corporation
  • 17. 17 Emulex Confidential - © 2013 Emulex Corporation
  • 18. 18 Emulex Confidential - © 2013 Emulex Corporation
  • 19. 19 Emulex Confidential - © 2013 Emulex Corporation
  • 20. 20 Emulex Confidential - © 2013 Emulex Corporation
  • 21. 21 Emulex Confidential - © 2013 Emulex Corporation
  • 22. 22 Emulex Confidential - © 2013 Emulex Corporation
  • 23. 23 Emulex Confidential - © 2013 Emulex Corporation
  • 24. 24 Emulex Confidential - © 2013 Emulex Corporation
  • 25. 25 Emulex Confidential - © 2013 Emulex Corporation
  • 26. 26 Emulex Confidential - © 2013 Emulex Corporation
  • 27. 27 Emulex Confidential - © 2013 Emulex Corporation
  • 28. 28 Emulex Confidential - © 2013 Emulex Corporation
  • 29. 29 Emulex Confidential - © 2013 Emulex Corporation
  • 30. 30 Emulex Confidential - © 2013 Emulex Corporation
  • 31. 31 Emulex Confidential - © 2013 Emulex Corporation A New Recording Paradigm EndaceProbe next generation sniffer 100% accurate traffic recording – Real 10 Gbps performance Up to 64 TB of local storage – Extensible via sledding or SAN Full flow-based traffic indexing – Including application classification Open and flexible – Endace Application Dock – Programmable RESTful API EndaceVision / Endace Packets
  • 32. 32 Emulex Confidential - © 2013 Emulex Corporation Total Datacentre Visibility
  • 33. 33 Emulex Confidential - © 2013 Emulex Corporation Conclusion Troubleshooting in a 10GbE world requires 10GbE capable tools Wireshark needs support to remain relevant in high-speed environment EndaceVision & Endace Packets solve the scalability challenge 100% accurate recording is mandatory input – Dedicated purpose built hardware Long live Wireshark!
  • 34. 34 Emulex Confidential - © 2013 Emulex Corporation Thank you. jim.macleod@emulex.com www.emulex.com

Notes de l'éditeur

  1. To assure you that there’s no waving of hands, here’s a 60-second view of the traffic we’re using for the demo. This is a live capture in our demo lab of replayed previously captured data, so, while it’s got spikes in the small scale, you won’t see the daily variations you would on your own network. You can see from the timestamps on the screen that this data was taken yesterday, and that there are sustained traffic spikes above 6Gbps.
  2. Here’s what it looks like when viewing 10 minutes.
  3. Here’s 1 hour
  4. And just for fun, here’s 2 days.The trend you’re seeing is that, as we zoom out, the line flattens. There just aren’t enough pixels to show all of the spikes, so we’re having to do the same thing as all of the other tools out there: average the samples. But as network analysts, we like those spikes. We know that there are bursts and microbursts. So here’s what we at Endace have done.
  5. I turned on the Bursts display, which tracks the maximum bandwidth value for each display point, with a sample size of 1ms.
  6. Now I’m going to zoom back to 1 hour.
  7. Here’s 10 minutes.
  8. And back down to 1 minute.
  9. Now I’m going to pivot my view to Traffic Breakdown over Time, with a breakdown on Applications. This lets me see what’s going on at Layer 7. For this capture, we’ve got mostly RTP traffic out there – that’s VoIP. I can also see that someone is using a lot of iTunes, plus some http video, Amazon.com, etc. While RTP is probably business traffic, iTunes and Amazon almost definitely aren’t.
  10. I’m going to filter in on iTunes to see who’s using it.
  11. Here’s the filter applied. I’m going to pivot my view to see who’s sending this traffic.
  12. I’m still looking at the same data, but I pivoted to show the top talkers, with the iTunes filter. I also zoomed my timescale out to show the last 24 hours.There’s 1 internal host who’s really pulling the majority of traffic. You can see it on the left. The vast majority of its traffic is colored blue, to indicate that it’s receiving that data. Similarly, the 2 primary external servers are colored green.Just a reminder, this is our demo lab, doing a live capture of traffic that’s being replayed. I doubt iTunes in reality is capable of feeding 10T to a single client in 24 hours.
  13. I can also change the filter to remove the iTunes and see who else the node is talking to.
  14. Next question is what else this node is doing. It looks like, apart from iTunes, there’s not much else – some Facebook, a little generic http.
  15. We can uncover some of that generic http with the Conversations view.
  16. What I really want is to know who this node is. Yes, I probably have other tools to find out – dynamic DNS might tell me. But I’m a packet geek, and I trust what the packets tell me. So I’m going to download the mdns packets and see the advertisements from the node itself.I’m going to download the packets to the probe. It keeps them off my laptop to keep it from potentially going into PCI scope. It also means I don’t tie up my laptop in the download if it’s a large file, and my teammates can also access it if they need to.
  17. Here’s where we look at the download – there’s a progress indicator, time remaining, etc, but the cool part is that I don’t have to wait for the download to complete, so I clicked on Packets.Notice that you can also download these directly as either PCAP or ERF. ERF is the Endace format for packet capture.
  18. Endace Packets looks like Wireshark, because it’s the tool that our customers said they use most often.There’s a lot of mdns out there, let me filter it down to something tighter.
  19. I filtered for DNS responses of type PTR, mapping the IP or IPv6 address to the hostname, then used the “contains” filter to narrow down the search to mdns .local names. I’ll dig a little more into the first packet now.
  20. And there’s the culprit. The device identifies itself as “Neil L’s iPhone”. Now I can go have a chat with Neil about proper use of the local resources.
  21. Just to be thorough, I also did a local download – on the probe – for some of that unidentified http traffic. Here I’ve got a filter applied to focus only on the packets which have a http request URI, which will tell me what domains the iPhone is connecting to.
  22. Since EndacePackets does name resolution, it also does name de-resolution, which is useful for cases like this, where everything is going either to the Amazon cloud or to cloudfront. Just hover over a name and the address will pop up.
  23. And there’s the real URI for the request. You can also see the User-Agent. CFNetwork is a sockets API in IOS, so it looks like this is an app, probably pulling down an advertisement.
  24. I’ll scroll to the right and you can see the list of relative URIs – this BYOD stuff gets pretty chatty, but that’s a different vendor.