Observer GigaFlow

Documentation

Table of Contents

Observer GigaFlow Documentation

Documentation > How-To Guide for GigaFlow > Alerts and Events > Investigate a SYN Anomaly

Investigate a SYN Anomaly

See Reports > System Wide Reports > SYN Forensics Monitoring in the Reference Manual.

GigaFlow monitors all TCP flows where only the SYN bit is set. In normal network operations, this indicates that a flow has not seen a reply packet while active in a router's Netflow cache.

A lonely SYN can be an indicator that:

  • Routing was asymmetric. Perhaps the reply returned via a different router.
  • Reply traffic was blocked.
  • Servers were not responding for some reason.
  • Something was probing the network.

To view objects that are behaving anomalously, navigate to Reports > System Wide Reports > SYN Forensics Monitoring

You will see a summary of all the internal sources listed in order of the number of destination objects associated with each internal source.

Click the Drill Down icon Drill down icon. for more information about each IP address.