ManageEngine OpManager NetFlow Plug-In
Welcome to the ManageEngine NetFlow Analyzer Read Me. This Read Me file contains information about the current release, along with system requirements and installation instructions for the Windows and Linux builds of NetFlow Analyzer.
About ManageEngine NetFlow Analyzer
ManageEngine NetFlow Analyzer is a web-based bandwidth monitoring tool that collects NetFlow data exported from routing devices, and uses it to analyze and report on IP traffic across the network. With instant reports on top applications, protocols, conversations, and hosts, NetFlow Analyzer gives you valuable insight into bandwidth usage in your enterprise without the complexity and expense involved in a traditional WAN analysis setup.
For more information on NetFlow Analyzer, visit https://www.netflowanalyzer.com/
For more information on Cisco® NetFlow Services visit http://www.cisco.com/go/netflow
This Read Me is divided into the following sections:
- Release Features
-
10.2.5- Build 10250
NetFlow Analyzer 10.2.5 (Build 10250)
Features:
- Heat Maps : Heat maps in NetFlow Analyzer helps to visualize the health status of all the interfaces in a single page. It uses color codes to depict the severity of the monitored devices.
- QoS graphs : QoS graphs displays the real-time information of interface traffic in graphical format. This helps to get a better view of your interfaces and applications performance.
- API Client Enhancements :
- Add & Edit options included in IP Groups, Interface Groups & Alert Profiles.
- Add option included in DSCP & App Groups.
- Option to Add, Edit & Delete User Management.
- New segment named "Attacks" added inside Settings. It comprises of three settings,
- ASAM Setting:- Start/ Stop the flow processing for Advanced Security Analytics Module.
- Manage Config:- Enable/ disable the Problems, Resources and Algorithms involved in ASAM.
- Threshold Setting:- Basic and advance settings to update the threshold values in ASAM.
-
10.2 - Build 10201
NetFlow Analyzer 10.2 (Build 10201)
Features:
- Supports high-performance database named as "HighPerf Reporting Engine" for enhancing raw data storage and report generation.
- Manual raw data collection option for a Router.
- Option to clean up aggregated data.
- Option to "Exclude weekends" in alert profile.
-
9.9.0 - Build 9900
NetFlow Analyzer 9.9.0 (Build 9900)
Service Pack Released
- Cisco AVC monitoring reports - NBAR2 application reports, HTTP host reports, QoS class hierarchy reports, ART reports
- Support for Cisco NBAR2 (Ability to identify 1000+ applications by default)
-
9.8.6 - Build 9860
NetFlow Analyzer 9.8.6 (Build 9860)
Service Pack Released
-
9.8.0 - Build 9800
NetFlow Analyzer 9.8 (Build 9800)
Features
- NetFlow Configurator
- IPv6 support is extended to Historical data(aggregated data) reports, Application mapping, Top sites mapping, Schedule reports and Report profiles
-
9.7.0 - Build 9700
NetFlow Analyzer 9.7 (Build 9700)
Features
- Support for IP SLA Video Operations
- Google maps visualization v3
- Interface groups support in Billing module
- Source Network and Destination Network based Anamoly detection in ASAM module
- Option to ignore events for all resources in ASAM module
- IPv6 support in ASAM
- Facility to shut down ASAM module from admin settings page
- Support for Multicast Reporting
- Alert clone copy
- User interface has been re-vamped to suit Customer needs
- Support for Cisco's Medianet and Mediatrace technology
- Support for App-flow
- Create and Monitor IP groups using WAN RTT Monitor
- Edit Threshold Settings in WAN RTT monitor
- Generate on-demand bills in capacity planning reports.
- Option to schedule Capacity Planning reports and Medianet reports
- Customizable e-mail subject
- Performance tuning of product through user interface
- Option to Add, Modify, and Delete Top sites
- AS Number added in AS Report
- Option to Exclude week-end and Business Hour in capacity planing PDF and CSV
- Export reports in CSV format for Device and interface based Consolidated Report.
- Option to load DNS Names from CSV file
- View Top 20 interfaces in consolidated report view per page
- Option to Export reports in CSV format for IP Group consolidated report
- View IPSLA Collector name in GUI
- Global Search - Report Based sorting.
- New application names has been added
- Anomaly detection based on Source IP and Destination IP
- Heuristics based event classification that includes Denial of Service Attack,Host Scan, Port Scan, Diagonal Scan and Grid Scan
- Enrichment of events with location details(Geographical and Topological) for Offender IPs and Target IPs
- Customized user interface for white listing problem specific Flows and Events(Ignore Events and Discard Flows)
- Customized User Interface that includes
-- Enable/Disable specific Problem
-- Enable/Disable specific Algorithm
-- Enable/Disable Resources
- Algorithm Settings
-- Customized Algorithm specific Threshold configuration
-- Algorithm specific Offender/Target Field configuration
- Location(EventList report)
-- Customized Topological configuration for Offender IPs and Target IPs
-- Offender/Target Location Mode settings
- Security Posture dashboard - Problems & Time Lines
- Listing all the Problems with the Events(with Pie Chart) and
Resources(with Bar chart) for each Class
- Multi-line graph of Time showing occurences of Events, Resources and Problems
- Offenders & Targets dashboard - Resources & Time Lines
- Lists all the Resources along with the Events(Pie-Chart) and problems (with Bar chart) for each Algorithm Type
- Multi-line graph of Time showing occurences of Events, Resources and Problems
- Problem Analysis dashboard
- Lists all Resources along with the Events(with pie chart) for the specific Problem
- Multi-line graph of Time showing occurences of Events and Resources
- Resource Analysis dashboard
- Lists all problems along with the events(with pie chart) for the specific Resource
- Multi-line graph of Time showing occurences of Events and Problems
Bug Fixes
- Mail Authentication issues have been fixed
- Issues with incorrect speed graphs in the Dashboard have been fixed
- Cisco recommended QoS base line - PDF broken link has been fixed
- Service start-up issues in Windows 2008 have been fixed
- URL Related Security bug fixes
- Issues in Auto login has been fixed
- index page sorting has been fixed
- MySQLl IPv6 issue has been fixed
- MS SQl and empty page issue in WAAS has been fixed
- Application mapping duplication has been fixed
- Individual graph fix in non-English environment
- Enhancements in WAAS Reporting to support all CM versions
- Issue related to parsing IPSLA Monitor OID has been fixed
- Handled Request time out error in QoS polling
- CBQoS temp table split fixed
- Handled AS Number field in a different position and not in usual position of V9 Flow
- Report profile - report display issue on non-english environment
- Bill plan config script error in French language
- License management script error in Spanish language fixed
-
9.0.0 - Build 9000
NetFlow Analyzer 9.0.0 (Build 9000)
Major Features:
- Capacity Planning Report
- Report Profiles
- Top Sites
- Selection box for list of applications
- Compare report includes 95th percetile
- Compare report includes 1,5,15 min reports
- Resolve NATED Addresses in ASA reports
- Resizeable columns
- Automatic CBQoS configurations for the first 20 routers
- Schedule Reports CSV option
- Geo location PDF and CSV
- Schedule Business hours for last month and week
- Standard Deviation calculation in Traffic Report
- Interface performance dashboard
- Add custom URL widget in Dashboard
- Wide Area Application Services (WAAS)
- Support IPV6 Address Format
- Enhanced Capacity Planning Report
- Creating Alert Profile with IP Address as Criteria
- Report Filter Enhancements
- Option to map IP addresses to site names
- Scheduling Options for Compare Reports and Report Profiles
- Support for Radius server Authentication in MSSQL
- Enhancements to Consolidated Reports
- Network Snapshot Improved with Widget for Top N Alerts
- String Search Option for IP groups
- Custom Selection Option in Device Reports
Bug Fixes:
- The average for 5 / 15 Min Data point Average in traffic page has been fixed
- The junk characters in Non-english property file has been removed
- Sampling in Adtran Devices has been added
- Dashboard related issues have been fixed
- Consolidated Device based Report - (graph color related issue) fixed
- Schedule Report file names with "null" has been fixed
- Billing "Alert" issue has been fixed
- User Defined DNS added for Schedule reports
- Geolocation - "unaccounted" removed
- Dashboard - Topstat - Last 15 Min Report - time period wrong
- Dashboard related issues have been fixed.
- Tomcat Vulnerability issues have been fixed.
- Fix for Apache Tomcat SingleSignOn HTTP Cookie exposure Vulnerability (CVE-2008-0128)
- Hidden the webserver details (say Apache/Tomcat 5.0.28) and return a blank information for the sake of security.
- Fix for the multi-content-length vulnerability issue in Tomcat
- Fix for HTTP Cookie (jsessionid) Exposure Vulnerability
- Temp raw table growing issue has been fixed
- Index page sorting has been fixed
- SNMP V3 related issue has been fixed
- MailServer related issue has been fixed
- admin users sync issue has been fixed
- chinese language issue has been fixed
-
8.5.0 - Build 8500
NetFlow Analyzer 8.5 (Build 8500)
Feature:
Advanced Security Analytics Module. More information.
Bug Fixes:
- The average for 5 / 15 Min Data point Average in traffic page has been fixed
- The junk characters in Non-english property file have been removed
- Sampling in Adtran Devices has been added
- Dashboard related issues have been fixed
- Consolidated Device based Report - (graph color related issue) fixed
- Schedule Report file names with "null" has been fixed
- IPSLA fix
-
7.5.0 - Build 7500 (SP 2.0)
NetFlow Analyzer 7.5.0 (Build 7500)
Major Features:
- Customizable dashboard
- Site to site traffic monitoring
- GRE application filter
- Email option for sending reports with single click.
- Policy enabled (CBQoS) routers need not export NetFlow for CBQoS monitoring
- DSCP names in alerts and IP groups
- Volume based billing
- Secondary DNS server lookup
- Raw data storage - Can be stored for as less as one hour
- Report based on nexthop values.
- Localization available in 8 languages.
Minor Features:
- Password strength is displayed
- "Compare reports" can also be exported as PDF now.
- UAE Dirhams added in billing.
- Option to modify interface groups.
- Users can switch off raw data reports and generate reports from aggregated data, in case of time constraints
- Look and feel changed
- Subminute visibility available
Bug Fixes:
- Issues related to sFlow fixed.
- Day light saving time brought into effect. Product will automatically sync to the day light saving time change.
- AS view related bug fixed
- CBQoS related issues fixed
- Automatic deletion of older raw data in non-English-OS issue fixed.
- Issue with the "scheduled custom report" fixed
-
7.0.0 - Build 7002 (SP 2.0)
NetFlow Analyzer 7.0.0 (Build 7002)
Bug Fixes
- Issue related with "seeing data point only for the last ten minutes in the graphs" has been fixed.
- Inablility to start as a service in Linux has been fixed.
- Issue related to mysql crashing every 24 hours (typically at 2:00 am every day - while loading DNS entries) has been fixed.
- Issue related to mail receiving and mail attachment in scheduled reports has been fixed.
- NetFlow Analyzer temporary images stored in the OS tmp folder will be periodically cleaned up.
-
7.0.0 - Build 7001 (SP 1.0)
NetFlow Analyzer 7.0.0 (Build 7001)
Major Features
- Usage based billing
- Localization supported
- Reporting on source network and destination network
- Look and feel changed
Minor Features
- Option to resolve DNS for single IP addresses.
- Quick view graph from the dashboard view for IP groups.
Bug Fixes
- Application mapping with IP addresses will be categorized in the order in which they were created.
- Ordering of interface list in the browsing of older scheduled reports.
- Average calculation bug in scheduled custom report has been fixed.
-
7.0.0 - Build 7000 (Beta)
NetFlow Analyzer 7.0.0 (Build 7000)
Major Features
- Reporting on Cisco CBQoS - Useful for monitoring class based pre and post policy traffic usage, class based drops and queuing.
- Authentication using radius server
- Ability to create IP groups with exclude IP address option
- Ability to add application mapping from the Show Ports page for enhanced usability
- DNS resolving enhancement of source and destination addresses
- Support for user configurable DNS names for IP addresses
- Different IN and OUT speed can be configured for interfaces
- Support for exporting reports to CSV
- Sorting on the Autonomous Systems view for easier tracking and for peering arrangement
- Option to exclude ESP_App on user defined interfaces - Ensures that traffic is not double counted in case of ESP tunnels.
- Option to suppress output interface accounting on user defined interfaces - Useful when working with WAN accelarators
- Option to suppress ACL(Access Control List) related drops (based on destination interface being null) on user defined interfaces
- Quick view traffic graph in Dashboard view for enhanced usability
- Graphs enhanced to one min granularity and also to real-time in Network Snapshot
- Ability to set snmp parameters globally for all routers
- Support for sorting of interfaces based on usage in Dashboard View
- User management enhanced to provide last login time and current login status for all users
- The LHS view can be re-arranged for convenience
- Support for configuring alerts on interface groups. Interface groups can be used for checking the router traffic by combining all the interfaces into a single group.
- User permission can be granted at a interface group level. This feature would enable providing permission at an interface level while creating a user
- Option to view older schedules reports from the UI
Minor Features
- Login page enhanced with a "keep me signed in" option
- Alerting can be disabled for non-business hours
- Ability to Backup.bat just the aggregated data
- Option to bulk-load IP groups from flat file
- Distribution graph for troubleshooting, custom reports and drill down reports
- Configurable deletion of older alerts
Bug Fixes
- Bug related to scheduled report attachment resolved
- Today report to have only values from 00:00 to current time
-
6.1.0 - Build 6100
NetFlow Analyzer 6.1.0 (Build 6100)
Major Features
- Network Snapshot View brought in
- Global Comparison Report feature added
- QoS reporting brought in
- Alerting for IP group added
Minor Features
- DSCP Group brought in
- Distribution Graph for Conversation added
- Support for mail in HTML format
Bug Fixes
- Issue in average calculation and monthly report drilldown to 1 min code addition fixed
- TCP FLAGS is not reported correctly - fixed
- Issues related to google map fixed
-
6.0.0 - Build 6001
NetFlow Analyzer 6.0.0 (Build 6001)
Major Features
- Real time reports with graphs updates immediately as the data is received
- Support for sFlow data capture and reporting
- Option to click and drag on the graph for easier drilldown
- IN and OUT traffic (in bytes and packets) for each interface maintained with 1 minute granularity for upto 1 year
- Performance improvement in IP group classification engine
- Integration with Google Maps for a better view of the network
- Ability to report on DSCP mapping
- Alerting feature enhanced to send an alert when link goes down or when no flows are received for 15 minutes
- Ability to group together applications into a single logical entity
Minor Features
- Exporting pages to PDF
- More options in the scheduled reports (Modify reports, speed / utilization, IP / DNS and option to zip or not zip the reports)
- Option to back up configuration data
- Source and Destination dissemination (to see how many unique destination that a source talked to and vice versa).
- Individual graph for each source, destination and application
- NBAR storage period extended to 1 year
- Option to disable an IP Group
Bug Fixes
- Bug related to random interfaces appearing with NetFlow V9 has been fixed
- Bug in alert mail classification has been fixed
- Ambiguity in Min and Max points with respect to the graph has been resolved
-
5.5.0 - Build 5505 (SP 1.2)
NetFlow Analyzer 5.0.0 (Build 5505)
Major Features
- Full i18N compliant
- Localized setup in Chinese, Croatian, Dutch, French, German, Japanese, Spanish languages
Bug Fixes
- Exporting V9 flows will report large number of interfaces than the actual number. This issue has been fixed
-
5.5.0 - Build 5502 (SP 1.1)
NetFlow Analyzer 5.5.0 (Build 5502)
Major Features
- Reporting on NBAR statistics
- Support for netflow V9
- Automatic Scheduling and emailing of reports
- Associating IP address in application mapping (in addition to the port and protocol available now)
- Ability to create interface group - ability to group interfaces together and monitor traffic
- Reporting on ToS and TCP_Flag
- Ability to listen on multiple UDP ports for incoming NetFlow datagram packets
- Option to retain raw data for upto 30 days.( earlier limit was 2 weeks)
Minor Features
- 95-th percentile added in traffic graph.
- Configurable from address for emails - both in alert emails and scheduled reports
- logZipUtil.bat to include .err file in mysql\data folder
- Back-Up DB will have the backup location as configurable and also have option to overwrite the old backup
- IP Groups list sorted by name
- Values for the first few minutes were not plotted in the last traffic graph. This issue has been fixed.
- Ability to enable/disable collection of AS information based on user's needs.
Bug Fixes
- Alert will not be generated for interfaces whose interface index is 0.
- Bug in NetFlowAnalyzer MIB for SNMP trap (Variables do not correspond to trap varbind order) has been fixed.
- When reports are scheduled and automatically emailed, the files and the folders have been appropriately named for easier identification.
-
5.0.0 - Build 5001 (SP 3)
NetFlow Analyzer 5.0 Beta (Build 5001)
Major Features
- Threshold-based alerting - option to send e-mail notifications and SNMP traps based on alerts
- Increased granularity - option to configure maximum time period for retaining raw data (upto 2 weeks)
- Enhanced IP group management - option to modify IP groups and associate interfaces to IP groups
- Internationalization - option to support local languages (French, German, Spanish, Japanese, and Chinese are available out-of-the-box)
Minor Features
- Option to view IfName and If Alias values for an interface in addition to IfDesc value.
- Dashboard filters - option to set filters on interfaces displayed on the Dashboard, based on the percentage of incoming and outgoing traffic received.
- Enhanced Traffic Filter - option to view hour-based traffic data in daily and weekly traffic graphs.
- Support link - Separate link with several options to contact NetFlow Analyzer Technical Support in case of any problems
-
4.0.2 - Build 4020 (SP 2)
NetFlow Analyzer 4.0.2 (Build 4020)
Major Features
- Support for NetFlow version 7
- Reporting based on AS information
- Localized setup in Chinese, and Japanese languages
Minor Features
- Reporting based on packet count
- Port range in mapping applications
Bug Fixes
- Fixed PDF loading issue in Acrobat Reader 6.0
- Fixed color bug in Dashboard percentage values
- Fixed bug in IP address range when incorrect values were entered
-
4.0.1 - Build 4010 (SP 1)
NetFlow Analyzer 4.0.1 (Build 4010)
Major Features
- Address Grouping - Create monitoring and reporting groups based on IP addresses or applications
- Custom reports across multiple interfaces and devices
Minor Features
- Criteria to define ports and port ranges in custom reports
- Database archiving - Utility that makes a backup of the database.
- Support file creation - Utility that zips the log files and database information to send to the NetFlow Analyzer Support Team.
- Traffic graphs made as non-stacked graphs, and shown as a combination of line and area graphs
- Interface Traffic graphs shown in one-minute intervals
Bug Fixes
- Both In and Out traffic of managed interfaces are maintained - Previously traffic was accounted for flows whose source interface was managed. Now traffic is accounted for flows whose source or destination interface is managed.
- Fixed mismatch in total number of interfaces marked as managed in DB and memory
- Fixed PDF loading bug - Error when exporting to PDF when server was installed in non-"C" drive.
- Fixed Applications graph bug - graph was hidden when more than 100 applications were listed.
- runQuery.jsp file works fine on Linux platforms
-
4.0.0 - Build 4002
NetFlow Analyzer 4.0.0 (Build 4002)
Bug Fixes
- Fixed threading issues in updating database while handling more than 250 interfaces
- Fixed issue in determining number of managed interfaces in License Management
- Fixed application port bug - minimum value of ports was assigned to an application. Now whichever source or destination port maps to the application is used. Apart from this, source and destination ports are now displayed for unknown applications.
- Fixed Delete Router bug - when all interfaces of a disabled router were deleted, new flows from any interface on that router were not processed. Now fixed to enable the router when all its interfaces are deleted. This ensures that if this router starts sending flows again, these incoming flows are processed.
- Fixed percentage utilization bug in traffic reports - value was exceeding 100% in some cases.
- Fixed Update Router Settings bug - device is now scanned again even if no changes have been made to Router Settings.
- SNMP requests to routers sent in batches to ensure better response
Minor Features
- NetFlow Analyzer can be run as a service on Linux
- Update Manager tool included - tool to apply, manage, and remove service packs and patches
- Option to edit Device Settings is available only for Administrator and Operator users
- Application Mapping list is sorted on Application name for easy access
- More enterprise applications added to the list of applications supported
- NetFlow Analyzer can be run as root/non-root user
- Server can be started in non-X-windows (headless) environment in Linux/Solaris
-
4.0.0 - Build 4001
NetFlow Analyzer 4.0.0 (Build 4001)
Bug Fixes
- Fixed time zone-related bug causing problems in setting Start and End time in graphs
- About and Feedback links made to open in separate windows
-
4.0.0 - Build 4000
(GA)
NetFlow Analyzer 4.0.0 (Build 4000)
General Features
- Support for NetFlow version 5 exports
- Web-based interface for viewing the network as well as performing administrative tasks
- Configurable applications and application ports
- Support for logical grouping of routers
- Three user levels with different privileges, to enable managing of groups
Graphs & Reports
- Instant graphs of network utilization per network interface
- Daily, weekly, and monthly reports showing current, average, and peak traffic patterns on an interface, as well as percentage utilization
- Reports on Top Applications, Top Sources & Destinations, and Top Conversations
- Resolvable source & destination addresses
- Reports include protocol & bandwidth utilization information
- Subnet-based and IP range-based reports
- Consolidated reports to show Top Application, Top Source, and Top Destination for an interface in one report
-
System Requirements
2.0 System Requirements
The specifications of your system depends on the number of routers sending NetFlow exports to NetFlow Analyzer, as well as how busy the actual router is. The minimum requirements for the system on which NetFlow Analyzer needs to be installed are given below.
Hardware Requirements
- 2.4 GHz Pentium 4 processor or equivalent
- 1GB RAM
- 10GB disk space for the database
- Monitor that supports 1024x768 resolution
Supported Platforms
- Windows Vista
- Windows 2000 Server/Professional with SP4
- Windows XP with SP1
- RedHat Linux 8.0, 9.0
Supported Web Browsers
- Internet Explorer 5.5 and above
- Netscape 7.0 and above
- Mozilla 1.5 and above
Note on NetFlow Support:
Ensure that the routing device supports NetFlow or sFlow , and is exporting NetFlow version 5, 7 or 9 only. Refer the User Guide for more information on NetFlow export.
-
Installation and Setup
3.0 Installation and Setup
Detailed installation instructions are given in Installation and Setup section of the User Guide. Router setup information is also included in the same document. Specific sections include,
-
Contact Information