You can use the monitor command to configure details relevant to monitoring charts and the monitoring data that is collected.You can configure how the data is displayed, how the traffic is analyzed for monitoring purposes, which order of resolution methods are tried when resolving IP addresses to hostnames, whether data is collected, and whether collected data is deleted.
monitor apm
To set the normalization size for APM calculation:
monitor apm transaction normalize <value>
monitor {bit-torrent|edonkey|openvpn|sensitivity|skype}
To set bit-torrent monitoring sensitivity:
monitor bit-torrent sensitivity {high|med|low}
To set eDonkey monitoring sensitivity:
monitor edonkey sensitivity {high|med|low}
To specify the sensitivity of the openvpn traffic monitoring:
monitor openvpn sensitivity {aggressive|safe}
To set the minimum number of packets needed before it is monitored:
monitor sensitivity <sensitivity>
Setting this to a low value is not recommended in high load environments. When the sensitivity is set to a low value such as 9, flows that contain less than nine packets over a five minute period are not stored in the database. This prevents port scans from loading hundreds of unnecessary rows of data into the database.
To set Skype monitoring sensitivity:
monitor skype {high|med}
monitor display {chart-size|graphing|real-time|table-size|url-size}
To modify how monitoring screens are displayed:
monitor display {chart-size|graphing|real-time|table-size|url-size}
monitor host-resolution
To control the order of resolution methods tried when resolving IP addresses to hostnames:
monitor host-resolution {DNS|IP|Netbios|Network_Object} rank <ranking order>
There are multiple host resolution methods that can be used to resolve IP addresses to hostnames. The system will attempt to resolve the hostname using one of the methods. If that method fails it will try another method. You can determine the order of host resolution methods that the system will use by ranking the first method as 1, the next as 2, and so on.
E X A M P L E monitor host-resolution Network_Object rank 1 monitor host-resolution Netbios rank 2 monitor host-resolution DNS rank 3 monitor host-resolution IP rank 4 |
[no] monitor {dual-bridge-bypass|layer7|linklocal|asam}
To enable viewing flow data in the real-time monitor per bridge or merged into a single flow:
[no] monitor dual-bridge-bypass
To enable layer7 monitoring:
[no] monitor layer7
When disabled, the Layer 7 signatures within packets are not analyzed and any application detection objects with Layer 7 rules are ignored.
To enable IPv6 link local traffic monitoring:
[no] monitor linklocal
To configure Application Specific Analysis Modules (ASAM) settings, which enables/disables drill-down monitoring capabilities for the specified application:
[no] monitor asam {anonymousproxy|apm|asymm-route|citrix|dcerpc|http|ssl|urllog|voip} enable
anonymousproxy - When enabled, the system attempts to match the HTTP hostname and SSL common name against the list of anonymous proxy URLs downloaded by the appliance daily.
Disable this module if it appears that an applications is being misclassified as anonymous proxy.
apm - When enabled, this module calculates the network delay, server delay, round trip time (RTT), loss, efficiency, and TCP health for TCP connections.
Disable this module if the RAM or CPU usage is increasing and affecting the performance of the appliance.
Disable this module to stop the appliance in locations where privacy policy does not permit this type of user identification.
dcerpc - When enabled, this module watches for client requests for Microsoft services such as MAPI and SMB.
http - When enabled, this module attempts to further analyze connections identified as HTTP and attempts to extract information such as the host, URL, request type, and content type.
[no] monitor {ignore-internal|statistics}
To enable ignore internal to internal traffic:
[no] monitor ignore-internal
To enable collecting statistics:
[no] monitor statistics {subnet|subnet-application|virtual-circuit} enable
monitor clear
To clear stored monitoring data:
monitor clear {all|apm|appliance|subnet|aps|interface|monitor|network|optimizer|reduction|sla}
show monitor {diagnostics|setup}
To display the diagnostic configuration, such as graphing format, Layer 7 monitoring, host resolution, and monitoring database status:
show monitor diagnostics
To display the monitoring configuration:
show monitor setup
|
|