Differences
This shows you the differences between two versions of the page.
en:dpi:qoe:use_cases:triggers_setup:start [2023/08/30 08:53] – created elena.krasnobryzh | en:dpi:qoe:use_cases:triggers_setup:start [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== Triggers in QoE ====== | ||
- | {{indexmenu_n> | ||
- | |||
- | Triggers are used to search for data in QoE Stor according to the specified parameters. After the trigger is fired, one of the following actions is possible: | ||
- | * GUI notification | ||
- | * HTTP action | ||
- | * sending email | ||
- | |||
- | Required SSG options: | ||
- | * [[en: | ||
- | * [[en: | ||
- | Required additional modules: | ||
- | * [[en: | ||
- | * [[en: | ||
- | ===== Trigger configuration example: Finding the source of a Flood DDOS attack ===== | ||
- | |||
- | === General Information === | ||
- | |||
- | {{ en: | ||
- | |||
- | Trigger name «Source of DDoS», days of week – all, check frequency – every hour, number of positives – once, time and date of start/end - not specified. | ||
- | |||
- | < | ||
- | |||
- | === Queries === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * Add a field | ||
- | * Name: A | ||
- | * Choose a table to be scanned: Raw full netflow -> Tables -> Attacks detection -> Top hosts IPs -> Maxi | ||
- | * Set the period from: «now – 15minute», | ||
- | |||
- | < | ||
- | |||
- | === Conditions === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * Add " | ||
- | * Bind – AND | ||
- | * Function – avg | ||
- | * Serie in the 1 field – session timeout <= 20(ms) | ||
- | * Serie in the 2 field – number of sessions >= 1500 | ||
- | |||
- | < | ||
- | |||
- | === Error handling === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * In the field "If no data" — No data | ||
- | * In the field "If execution error or timeout" | ||
- | |||
- | < | ||
- | |||
- | === Actions === | ||
- | == E-mail == | ||
- | |||
- | {{ en: | ||
- | |||
- | * For automatic filling - click on the "</>" | ||
- | * In the field "Send to" — specify email address | ||
- | |||
- | < | ||
- | |||
- | == Notification == | ||
- | |||
- | {{ en: | ||
- | |||
- | * For automatic filling - click on the "</>" | ||
- | * Choose the notification type — " | ||
- | * With this setting, a notification will be created in the SSG | ||
- | |||
- | {{ dpi: | ||
- | |||
- | You can get a link to the report in the notification menu | ||
- | |||
- | {{ dpi: | ||
- | |||
- | Select notification \\ | ||
- | Select - " | ||
- | |||
- | {{ dpi: | ||
- | |||
- | Follow the link to the report - it will open in a new tab. | ||
- | |||
- | == HTTP == | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * For automatic filling - click on the "</>" | ||
- | * Choose the method most suitable for your ticket system and enter the URL | ||
- | |||
- | <note important> | ||
- | |||
- | ===== Trigger configuration example: Finding the target of a Flood DDOS attack ===== | ||
- | It differs from the previous example in setting 2 and 3 stages (Queries and Conditions). | ||
- | |||
- | === Queries === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | In the " | ||
- | |||
- | === Conditions === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | Serie — "Flow volume to subscribers", | ||
- | |||
- | <note important> | ||
- | |||
- | ===== BotNet Analysis ===== | ||
- | It differs from the previous example in setting 2 and 3 stages (Queries and Conditions). | ||
- | |||
- | === Queries === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * Choose Raw full netflow -> Tables -> Attacks detection -> Top application protocols -> Maxi for the " | ||
- | * Raw full network -> Tables -> Raw log -> Full raw log for the " | ||
- | |||
- | === Conditions === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | Most often, BotNet uses ports 6667 and 1080 — add each destination/ | ||
- | < | ||
- | |||
- | <note important> | ||
- | |||
- | ===== Subscriber' | ||
- | === General information === | ||
- | |||
- | {{ en: | ||
- | |||
- | Trigger name «Subscriber' | ||
- | |||
- | < | ||
- | |||
- | === Queries === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * Add " | ||
- | * Name А \\ Choose a table to be scanned: Raw clickstream -> Tables -> Raw clickstream | ||
- | * Name B \\ Choose a table to be scanned: | ||
- | * Set the period from: "now – 1 hour", | ||
- | |||
- | < | ||
- | |||
- | === Conditions === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * Add " | ||
- | * First field — choose table " | ||
- | * Second field — choose table " | ||
- | |||
- | < | ||
- | |||
- | === Error handling === | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * In the field "If no data" — No data | ||
- | * In the field "If execution error or timeout" | ||
- | |||
- | < | ||
- | |||
- | === Actions === | ||
- | == E-mail == | ||
- | |||
- | {{ en: | ||
- | |||
- | * For automatic filling - click on the "</>" | ||
- | * In the field "Send to" — specify email address | ||
- | |||
- | < | ||
- | |||
- | == Notification == | ||
- | |||
- | {{ en: | ||
- | |||
- | * For automatic filling - click on the "</>" | ||
- | * Choose the notification type — " | ||
- | * With this setting, a notification will be created in the SSG | ||
- | |||
- | {{ dpi: | ||
- | |||
- | You can get a link to the report in the notification menu | ||
- | |||
- | {{ dpi: | ||
- | |||
- | Select notification \\ | ||
- | Select — " | ||
- | |||
- | {{ dpi: | ||
- | |||
- | Follow the link to the report — it will open in a new tab. | ||
- | |||
- | == HTTP == | ||
- | |||
- | {{ dpi: | ||
- | |||
- | * For automatic filling — click on the "</>" | ||
- | * Choose the method most suitable for your ticket system and enter the URL | ||
- | |||
- | <note important> | ||