Network Detection Excessive Host Access
The Network Detection - Excessive Host Access insight displays anomalies when a device exceeds a defined threshold of host connections within a specific time window. For each client, the baseline for historical data uploads is first established over a 30-day period. Based on the client-specific baseline, this feature automatically detects and flags excessive host access. If no anomaly is detected, this insight is not displayed in the Insights page.
To access the insight, complete the following steps:
-
Access the Insights page. For more information, see Accessing Insights Page.
-
Click the Network Detection - Excessive Host Access tile.
The Network Detection - Excessive Host Access metrics displays the client information where the anomaly was triggered.
-
Select the client to see more details.
Figure 1: Behavior Mapping
In the Behavior Mapping chart, you can view the details of the anomaly. Hover over the chart to see the metrics of the Unique Hosts Visited.
The Host Access table lists all the anomalies detected for the client. You can view the details of the anomaly:
-
Source Role—Displays the role assigned to the client.
-
Unique Hosts—Displays the number of unique hosts.
-
Date—Displays the date when the anomaly was detected.
To view further details of the source, click the drop-down arrow next to the source. The following metrics are displayed:
-
Source IP: Displays the IP address of the source.
-
Destination: Displays the destination IP address of the device.
-
Destination: Displays the destination OS of the source.
-
Flow: Displays the number of
Note:Only the top 10 destinations of the source is displayed.
-