Efficient Workflow using Endace Fusion APIs - v2

2 downloads 163 Views 1MB Size Report
Commercial, open-source and custom applications. • Shrink-wrapped ... EndaceVision. • Browser-based GUI tool for sea
Efficient Workflow using Endace Fusion APIs and Dynatrace DC RUM

Investigation Challenges Overwhelming workloads •

Alert volumes make manual triage unsustainable

Need faster investigation and resolution • • •

Automate and streamline real-time investigations Definitive evidence for root cause identification Deep, back-in-time historical investigation

Operations teams need a shared view of what’s happened • •

Page 2

Common source of definitive evidence Eliminate inter-team finger pointing

© Endace 2016 | Public Distribution Permitted

Investigations Leveraging Network History The network is the key • • •

All activity takes place on the network – but networks have no memory Recording packet-level history provides definitive evidence of what’s happened A fabric of network recorders can provide network-wide history

Give all your tools access to Network History • • •

Endace Fusion APIs provide powerful workflow integration Commercial, open-source and custom applications Shrink-wrapped connectors for Fusion Partner apps

Deep, back-in-time historical analysis •

Page 3

Playback Network History for offline historical analysis and investigation

© Endace 2016 | Public Distribution Permitted

EndaceProbe Network Recorders 100% accurate recording, 10Mbps to 100Gbps • Open platform – API for streamlined workflow with partner apps – AFV hosting of virtualized analytics applications

• Days to months of network history storage Flexible and scalable fabric • Centralized recall and investigation • Centralized management, ultra-scalability Built-in investigation tools • EndaceVisionTM and EndacePacketsTM Page 4

© Endace 2016 | Public Distribution Permitted

Built-in investigation tools EndaceVision • Browser-based GUI tool for searching and visualizing Network History • Zoom in and out to look at pre-cursor or post-event traffic • Identify packets of interest for analysis EndacePackets • Browser-based packet decode tool based on WiresharkTM • Analyze packets directly on the EndaceProbe

Page 5

© Endace 2016 | Public Distribution Permitted

Workflow Integration using Fusion APIs Powerful REST APIs for streamlining workflows Pivot to Packets •

Pivot directly from an alert in a 3rd-party app (like DC RUM) to relevant packets for analysis

Pivot to Vision • •

Page 6

Pivot from a 3rd-party app directly to a visualization of related network history Can go directly from a visualization to EndacePackets

© Endace 2016 | Public Distribution Permitted

Host 3rd-Party Analytics Applications Host Applications in Application DockTM on EndaceProbes • Quickly deploy analytics across EndaceProbe estate using centralized orchestration • Hosted applications have full access to real-time traffic and recorded Network History Playback Network History to hosted applications • Slowly for deep analysis • Quickly for fast, targeted investigations Host Dynatrace’s virtual AMD in Application Dock

Page 7

© Endace 2016 | Public Distribution Permitted

Dynatrace DC RUM Workflow Example

1

Page 8

© Endace 2016 | Public Distribution Permitted

Looking at Application Response issues in CAS Console

Dynatrace DC RUM Workflow Example

2

Page 9

© Endace 2016 | Public Distribution Permitted

Click on user to retrieve related packets from EndaceProbe history

Dynatrace DC RUM Workflow Example

3

Page 10

© Endace 2016 | Public Distribution Permitted

Search parameters are pre-filled

Dynatrace DC RUM Workflow Example

4

Page 11

© Endace 2016 | Public Distribution Permitted

Packets are retrieved for analysis in Wireshark or other packet decode tools such as DNA