The platform takes variety of inputs from the network and processes it to give results. These inputs can be:

  OTM needs the following informational fields from netflows: IN_BYTES, IN_PKTS, PROTOCOL, TCP_FLAGS, L4_SRC_PORT, IPV4_SRC_ADDR, L4_DST_PORT, IPV4_DST_ADDR,     LAST_SWITCHED, and FIRST_SWITCHED. For more details refer to https://www.plixer.com/support/netflow-v9/.

Other streaming telemetry such as supported SIEM data can be used as an aggregator and the aggregated logs can be sent to CCE.

Please note that it is not mandatory to get all the above sources of information from every network but we need to ensure that there is atleast one flow source( either sflow or netflow), and one log source(identity logs from windows) redirected for complete visualization. At the same time, you can redirect sources as many as you want.

Configurations

This section has various subsections referring to the instructions of configuring data from various logs/flows sources to the Seceon CCE. Please refer to the respective subsection based on your requirement.