Skip to main content
All CollectionsProduct InfoSecurity
Traffic Behavior Investigation
Traffic Behavior Investigation
Alex Patnick avatar
Written by Alex Patnick
Updated over a month ago

Faddom now allows you to compare the traffic of the port on a specific connection for two timeframes. This will assist you in performing root-cause analysis, identifying deviations from normal operations, and determining impacts.

For example, you can examine server connections before and after an anomaly, focusing on significant traffic changes. This could provide insight into what occurred and help you perform root-cause analysis.

For best results, it is recommended you set up Anomaly Detection and Notifications and Events so you can be notified when something happens.

To set up the investigation you need to do the following -

  1. Find the server you are interested either through Search or on one of the maps

  2. Open the properties by left-clicking on the server

  3. Either click on Anomalies or open up the full properties and select Investigate

  4. Select the time stamps you want.
    ​Note - how far you can investigate depends on how long you keep the topology history. By default, this is seven days

  5. Click Go and you will be presented with the results to investigate
    ​
    ​

Investigate.gif
Did this answer your question?