Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| en:dpi:qoe_analytics:cases:network_health:triggers_setup [2025/10/30 13:08] – elena.krasnobryzh | en:dpi:qoe_analytics:cases:network_health:triggers_setup [2025/12/10 16:01] (current) – elena.krasnobryzh | ||
|---|---|---|---|
| Line 18: | Line 18: | ||
| === General trigger information === | === General trigger information === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| Trigger name: “DDOS source detection”, | Trigger name: “DDOS source detection”, | ||
| Line 26: | Line 26: | ||
| === Queries === | === Queries === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Add field | * Add field | ||
| Line 37: | Line 37: | ||
| === Conditions === | === Conditions === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Add two " | * Add two " | ||
| Line 49: | Line 49: | ||
| === Error handling === | === Error handling === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * “If no errors” — no data | * “If no errors” — no data | ||
| Line 59: | Line 59: | ||
| == E-mail action == | == E-mail action == | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Click the "</>" | * Click the "</>" | ||
| Line 67: | Line 67: | ||
| == Notification == | == Notification == | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Click "</>" | * Click "</>" | ||
| * Select notification type — “Warning” | * Select notification type — “Warning” | ||
| * A notification will be created in the SSG system | * A notification will be created in the SSG system | ||
| - | |||
| - | {{ : | ||
| The report link can be obtained from the notifications menu. | The report link can be obtained from the notifications menu. | ||
| - | |||
| - | {{ : | ||
| Select the notification | Select the notification | ||
| Click **Details** | Click **Details** | ||
| - | |||
| - | {{ : | ||
| Follow the report link — it will open in a new browser window. | Follow the report link — it will open in a new browser window. | ||
| Line 88: | Line 82: | ||
| == HTTP action == | == HTTP action == | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| Click "</>" | Click "</>" | ||
| Line 99: | Line 93: | ||
| === Queries === | === Queries === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| In the report field, select Raw full netflow → Tables → Attacks detection → Top subscribers → Maxi | In the report field, select Raw full netflow → Tables → Attacks detection → Top subscribers → Maxi | ||
| Line 105: | Line 99: | ||
| === Conditions === | === Conditions === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| Series — “Flow volume to subscribers, | Series — “Flow volume to subscribers, | ||
| Line 116: | Line 110: | ||
| === Queries === | === Queries === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Select Raw full netflow → Tables → Attacks detection → Top application protocols → Maxi for “A” | * Select Raw full netflow → Tables → Attacks detection → Top application protocols → Maxi for “A” | ||
| Line 123: | Line 117: | ||
| === Conditions === | === Conditions === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| Since BotNet often uses ports 6667 and 1080 — add each destination/ | Since BotNet often uses ports 6667 and 1080 — add each destination/ | ||
| Line 133: | Line 127: | ||
| === General trigger information === | === General trigger information === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| Trigger name: “Interest in competitors”, | Trigger name: “Interest in competitors”, | ||
| Line 141: | Line 135: | ||
| === Queries === | === Queries === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Add “+” field | * Add “+” field | ||
| Line 151: | Line 145: | ||
| === Conditions === | === Conditions === | ||
| - | {{ :dpi:qoe:use_cases: | + | {{ :en:dpi:qoe_analytics: |
| * Add 3 “+” fields | * Add 3 “+” fields | ||
| Line 161: | Line 155: | ||
| === Error handling === | === Error handling === | ||
| - | {{ :dpi:qoe:use_cases:competitors_errors.png? | + | {{ :en:dpi:qoe_analytics: |
| * “If no errors” — no data | * “If no errors” — no data | ||
| Line 171: | Line 165: | ||
| == E-mail action == | == E-mail action == | ||
| - | {{ :dpi:qoe:use_cases:competitors_email.png? | + | {{ :en:dpi:qoe_analytics: |
| * Click to auto-fill the form | * Click to auto-fill the form | ||
| Line 180: | Line 174: | ||
| == Notification == | == Notification == | ||
| - | {{ :dpi:qoe:use_cases:competitors_notifications.png? | + | {{ :en:dpi:qoe_analytics: |
| * Click "</>" | * Click "</>" | ||
| * Select notification type — “Warning” | * Select notification type — “Warning” | ||
| * A notification will be created in the SSG system | * A notification will be created in the SSG system | ||
| - | |||
| - | {{ : | ||
| The report link can be obtained from the notifications menu. | The report link can be obtained from the notifications menu. | ||
| - | |||
| - | {{ : | ||
| Select the notification | Select the notification | ||
| Click **Details** | Click **Details** | ||
| - | |||
| - | {{ : | ||
| Follow the report link — it will open in a new browser window. | Follow the report link — it will open in a new browser window. | ||
| Line 201: | Line 189: | ||
| == HTTP action == | == HTTP action == | ||
| - | {{ :dpi:qoe:use_cases:competitors_http.png? | + | {{ :en:dpi:qoe_analytics: |
| * Click "</>" | * Click "</>" | ||