Applicable for ENA v23.0 P01 upwards.
To view the details of a flow query
To load the filter portion of a flow query
To load the breakdown portion of a flow query
To reset the currently applied flow query to the default
Using flow queries on other servers and configurations
As of Entuity v23.0 P01 upwards, you can save the currently configured filter and breakdown that you've applied to a Flow Data dashlet as a flow query for reuse. You can choose to share a flow query with other users, and you can use the same flow query across other servers and configurations by downloading and then uploading the query.
There are two types of flow queries:
- Personal query: By default, a saved query is a personal query. A personal query can only be viewed, edited, and deleted by the user who created the query. The visibility of a personal query is on a per-user basis. Any user with 'Flow Viewing' permissions can save, edit, and delete their own personal queries and only their own personal queries.
- Shared query: A shared query can be viewed and loaded by all users with 'Flow Viewing' permissions, but can only be saved, edited, and deleted by users with 'Flow Query Management' permissions. For more information about user permissions, see this article.
The current query (filter + breakdown) that is applied to a dashlet can be reset to the default at any time. You can also choose to load only the filter portion of a flow query to a flow dashlet, or only the breakdown portion of a query, as needed.
To create a flow query:
- Navigate to the Flow Data dashlet.
- Click Save Query from the dashlet Overflow Menu.
The Flow Query form is displayed. - Enter the name of the flow query in the Name field.
- Toggle the Share option to Yes if you want to share the flow query with other users, or No to create the query for personal use only.
- Click the arrow next to the Breakdown field to manage the currently configured breakdown that you want included in the query.
The breakdown determines the type of flow information that is displayed in the Flow Data dashlet.
The Manage Breakdown form is displayed. - Do the following:
- Choose whether to perform DNS Lookup in the dashlet chart for the device source and destination columns.
If set to Yes, the FQDN device name is shown in the chart. If set to No, the source IP address of the device is shown. -
Optionally click the arrow next to the Count field to select one of the breakdown data metrics from the Groups field to be displayed in the Counts column in the dashlet table.
For example, if you select Application in the Count field, and then select Source in the Groups field, the Flow Data dashlet will display the Counts Application column in its table, and show the number of applications in that column for each source.
See Available Breakdowns for information on the breakdown data metrics. - Click the arrow next to the Groups field to select one or more groups of breakdown data metrics that you want to see in the dashlet.
See Available Breakdowns for information on the breakdown data metrics. - Click Done on the Manage Breakdown form to save your selection. Otherwise, click Cancel.
- Choose whether to perform DNS Lookup in the dashlet chart for the device source and destination columns.
- Click the arrow next to the Filter field to manage the currently configured filter that you want included in the query.
The Manage Filter form is displayed. - Do the following:
-
If rules already exist that you want to use in the filter, skip to step vi. Otherwise, to create a filter rule, click the (+) Create Flow Filter Rule field.
The Flow Rule form is displayed. - Enter the name of the flow rule in the Name field.
- In the Rule Item field, select one of the breakdowns available for this flow dashlet:
- Interface
- Interface In
- Interface Out
- Application
- Source
- Destination
- Protocol
- Host
- Port
- Port In
- Port Out
- QoS Class
- IP Precedence
- DSCP
- Ingress/Egress
- Application (Inside VXLAN)
- Host (Inside VXLAN)
- Source (Inside VXLAN)
- Destination (Inside VXLAN)
- Protocol (Inside VXLAN)
- Port (Inside VXLAN)
- VXLAN ID.
- Once you have selected a breakdown, the form updates with the specific items available for that selected breakdown.
For example, if you selected Port Out in the previous step, you can then specify the port number in the Port field that is displayed. Or, if you selected Ingress/Egress, you can then select N/A, Ingress or Egress in the fields that are displayed. - Click Save to save the flow rule and return to the Manage Flow form. Otherwise, click Cancel to exit the form without saving.
- Delete any unwanted filter rule(s) from the filter by selecting the checkbox next to the filter rule(s), and clicking Remove.
- To optionally view and edit the details of an existing filter rule, click the arrow to the right of the filter rule.
The Flow Rule form is displayed, where you can make edits, as needed. (See step i.) - Click Done to save the filter selections and return to the Flow Query form.
-
If rules already exist that you want to use in the filter, skip to step vi. Otherwise, to create a filter rule, click the (+) Create Flow Filter Rule field.
- Click Save on the Flow Query form to save the query. Otherwise, click Cancel.
To view the details of a flow query:
- Navigate to the Flow Data dashlet.
- Click Load Query from the dashlet Overflow Menu.
The Load Flow Query form is displayed. - Choose whether to load a personal or shared query by setting the Use a Personal Flow Query? option.
The queries are displayed on the form, based on your selection. - Click the arrow to the right of a query.
The Flow Query form is displayed for that query. - Click the arrow next to the Breakdown and Filter fields to view the details of the query.
Note, you can't edit filter or breakdown settings from the Flow Query form. To edit a flow query, see this section.
To load a flow query:
- Navigate to the Flow Data dashlet.
- Click Load Query from the dashlet Overflow Menu.
The Load Flow Query form is displayed. - Choose whether to load a personal or shared query by setting the Use a Personal Flow Query? option.
The queries are displayed on the form, based on your selection. - Click the flow query that you want to load, and click Load.
A green confirmation message is displayed, and the dashlet is then updated, according to the flow query settings. Otherwise, click Cancel.
To load the filter portion of a query:
- Navigate to the Flow Data dashlet.
- Click Load Filter from the dashlet Overflow Menu.
The Load Flow Filter form is displayed. - Choose whether to load a personal or shared filter by setting the Use a Personal Flow Filter? option.
Note, a custom flow filter is designated as personal or shared when you create a flow query.
The flow filters are displayed on the form, based on your selection. - Select the flow filter that you want to apply to the Flow Data dashlet, and click Load.
The dashlet is then updated, according to the filter settings. Otherwise, click Cancel.
To load the breakdown portion of a query:
- Navigate to the Flow Data dashlet.
- Click Load Breakdown from the dashlet Overflow Menu.
The Load Flow Breakdown form is displayed. - Choose whether to load a personal or shared flow breakdown by setting the Use a Personal Flow Breakdown? option.
Note, a custom breakdown is designated as personal or shared when you create a flow query.
The breakdowns are displayed on the Load Flow Breakdown form, based on your selection. - Select a breakdown to specify the type of flow information you want to see in the dashlet.
See Available Breakdowns for information on the breakdown data metrics. - Click Load to save your selections and exit the form.
The dashlet is then updated, according to the breakdown settings. Otherwise, click Cancel.
To edit a flow query:
- Navigate to the Flow Data dashlet.
- Click Load Query from the dashlet Overflow Menu.
The Load Flow Query form is displayed. - Load the flow query that you want to edit.
- Edit the filter portion of the query by clicking Configure Filter on the top-right of the dashlet or from the dashlet Overflow Menu. For more information about configuring flow filters, see this article.
- Edit the breakdown portion of the query by clicking Configure Breakdown on the top-right of the dashlet or from the dashlet Overflow Menu. For more information about configuring flow breakdowns, see this article.
- Click Save Query from the dashlet Overflow Menu.
The Flow Query form is displayed. - Make additional edits, if needed, and then click Save to save the flow query. Otherwise, click Cancel.
To reset the currently applied query to the default:
- Navigate to the Flow Data dashlet.
- Click Reset Query on the top-right of the dashlet or from the dashlet Overflow Menu.
A confirmation prompt is displayed. - Click Yes to apply the default flow query to the dashlet.
The dashlet is then updated, according to the settings of the default flow query. Otherwise, click Cancel.
Using flow queries on other servers and configurations
- To use flow queries on other servers and configurations, download the flow queries locally, and then upload the queries to another Entuity server or configuration.
- Note, personal flow queries can be used on the new server or configuration only by the same user who created the personal queries.
To download flow queries:
- Navigate to the Flow Data dashlet.
- Click Download Queries from the dashlet Overflow Menu.
The Download Queries form is displayed. - Choose whether to download shared or personal flow queries by setting the Use a Personal Flow Query? option.
The flow queries are displayed on the form, based on your selection. - Select the checkboxes next to the queries that you want to download, and click Download.
The query, or queries, are downloaded in a single JSON file.
To upload flow queries:
- Navigate to the Flow Data dashlet.
- Download the flow query, or queries that you want to use on a different server or configuration.
- Click Upload Queries from the dashlet Overflow Menu.
The Upload Queries form is displayed. - Click the arrow next to the Browse or Drop A File field, and navigate to the JSON file that you downloaded.
- Select the JSON file, and click Open.
The JSON file is then displayed on the Upload Queries form. - Click Upload.
A confirmation prompt is displayed, asking whether you want to continue. - Click Yes to upload the custom flow query, or queries, or click No to cancel.
To delete a flow query:
- Navigate to the Flow Data dashlet.
- Click Load Query from the dashlet Overflow Menu.
The Load Flow Query form is displayed. - If the query that you want to delete is shared, leave the Use a Personal Flow Query? option setting as No, otherwise set it to Yes.
The queries are displayed on the form, based on your selection. - Click the arrow to the right of the query that you want to delete.
The Flow Query form is displayed for the selected query. - Click Delete.
A confirmation window is displayed, confirming the deletion. - Click Yes to confirm the deletion or No to cancel.
Comments
0 comments
Please sign in to leave a comment.