1
23.7 Legacy Series / How to read the exported Insights
« on: September 07, 2023, 10:06:41 am »
I exported the reports from Insights but I can't find any documentation on the content and how to read them.
I attached a sample HTTPS session, and changed the IP to the corresponding machine label.
Here are my queries:
1. What does the last_seen column defines? Is it the actual time when those traffic was captured? If not, what does it define? I'm asking because I noticed the entire session completes immediately, which is impossible as the http session is firing a report page action (load/edit data) that would take some time to return the results.
2. What is the octets column for? Is this the size of the data being send/received in bytes?
3. em4 is my WAN interface and em3 my LAN interface.
- What does the in and out means for each interface?
- If in = into the interface, out = out of the interface, How do I read the entries in the attached, assuming it is sorted?
I attached a sample HTTPS session, and changed the IP to the corresponding machine label.
Here are my queries:
1. What does the last_seen column defines? Is it the actual time when those traffic was captured? If not, what does it define? I'm asking because I noticed the entire session completes immediately, which is impossible as the http session is firing a report page action (load/edit data) that would take some time to return the results.
2. What is the octets column for? Is this the size of the data being send/received in bytes?
3. em4 is my WAN interface and em3 my LAN interface.
- What does the in and out means for each interface?
- If in = into the interface, out = out of the interface, How do I read the entries in the attached, assuming it is sorted?