Quantcast
Viewing all articles
Browse latest Browse all 13537

Netflow - see what really happened

What industry is your company in?

 

Agriculture, Forestry, and Manufacturing

 

How large is your IT shop?

Small (1-250 elements)

 

Which SolarWinds product are you writing this review for?

Netflow traffic analyzer

 

What problem were you trying to solve when you purchased?

As a security analyst, I need the ability to see what happened on the wire after the fact.  Netflow is one of the most useful tools in my arsenal because it's not subject to the logging verbosity that any individual operating system or application might implement, but simply and clearly tells me which hosts were talking, on which ports, with how much data, for how long, and in some cases I can even see some of the initial packet contents.  I think of it light a camera at a traffic light after an accident occurs.  While several witnesses might have varying stories about who ran the light, the camera grabs clear objective evidence and removes all the speculation to quickly answer the question.  I use NTA all of the time to investigate suspicious activity and suspect hosts.

 

Did you consider options other than SolarWinds? Who?

Not for NTA, I've used it in other organizations and know it's intuitive interface and quickly can drill down to give me the query results I need without any excessive complexity.

 

How are you using the product and what benefits have you seen?

I use it as a security forensics tool, to investigate suspicious hosts and traffic patterns.  It quickly delivers a view as to exactly "who" said "what" and "when", making my life much easier.


Viewing all articles
Browse latest Browse all 13537

Trending Articles