Skip to main content

Traffic Behavior Investigation

Written by Itamar Rotem

Faddom now allows you to compare the traffic of the port on a specific connection for two timeframes. This will assist you in performing root-cause analysis, identifying deviations from normal operations, and determining impacts.

For example, you can examine server connections before and after an anomaly, focusing on significant traffic changes. This could provide insight into what occurred and help you perform root-cause analysis.

From v2026.2 and above, the investigation view also shows related operational events detected by Faddom and, when available, by external monitoring tools. These events provide additional context for the selected timeframe, so you can review traffic changes and detected issues in one place.

To set up the investigation you need to do the following -

  1. Find the server you are interested either through Search or on one of the maps

  2. Open the properties by left-clicking on the server

  3. Click on "Investigate"

  4. Select the time stamps you want.
    ​Note - You will only be able to select from the dates you have data for. By default, this is 14 days and can be changed in Settings > Global Parameters > Connection Storage and changing the Connection History Storage Days parameter.

  5. Click Go and you will be presented with the results to investigate

  6. The results include a summary of "Operational Events," "Users Logged In," and "Software Changes" detected for the selected server and timeframe. Click any item to open a searchable list of the detected entries.

Did this answer your question?