Server Activity Overview
With the Server Activity overview (ANALYZE > Overview > IP Traffic > Server Activity) you can view detailed data about servers that your organization’s computers have communicated with. You can then select specific processes that have been involved in the communication, and view details such as sent/received bytes and packets, response times, etc. for each process.
-
Specify required server, either by selecting it from the list, by specifying required Server hostname or by specifying required Server IP address (or parts of it).
-
In the Agents list, select the required location or group of computers.
-
Select the required Interval (that is the period of time that you want to cover). If the predefined intervals don’t suit you, select Custom to Custom Time Periods on Graphs.
-
Click the Update button.
Click the Update Simple or Update Detailed button.
- If you want to filter the results on a particular process that has been used in the communication, select the required process from the Process list and click the Update Simple or Update Detail button again.
Based on your parameters, the table lists some or all of the following:
- Server hostname: The name of the server that the computers communicated with.
- Server IP: The IP address of the server that the computers communicated with.
- Process name: Name of process used in the communication, for example chrome.exe.
- Process version: Version of process used in the communication.
- Port: The port through which communication took place, for example HTTP.
- Protocol: The protocol type used for the communication, TCP or UDP.
- Total response time: The time, in milliseconds, until the server/port response was received by all the computers on the server/port.
- Received bytes: The total number of bytes received by all the computers on the server/port.
- Sent bytes: The number of bytes sent from all the computers on the server/port.
- Received packets: The total number of IP packets received by all the computers on the server/port.
- Sent packets: The total number of IP packets sent from all the computers on the server/port.
- Retransmissions: The number of TCP retransmissions by all the computers on the server/port.
- Responses: The total number of TCP IP received by all the computers on the server/port.
- Requests: The total number of requests made by all the computers on the server/port.
- No application response within 500 seconds: The number of times that no application response with payload was received within a time frame of 500 seconds.
- [Response times grouped in milliseconds intervals]: The number of response measurements in the respective intervals by all computers on the server/port.
- Reports: The total number of times the server/port has been contacted by all computers.
- Connections: Total number of TCP connections to the sever/port by all computers.
- Connection resets: Total number of times that TCP connections to the sever/port were reset by all computers.