Efficient Workflow using Endace Fusion APIs - v2

8 downloads 121 Views 1MB Size Report
Playback Network History for offline historical analysis and investigation ... AFV hosting of virtualized analytics appl
Efficient Workflow using Endace Fusion APIs and Dynatrace DC RUM

Investigation Challenges Overwhelming workloads •

Alert volumes make manual triage unsustainable

Need faster investigation and resolution • • •

Automate and streamline real-time investigations Definitive evidence for root cause identification Deep, back-in-time historical investigation

Operations teams need a shared view of what’s happened • •

Page 2

Common source of definitive evidence Eliminate inter-team finger pointing

© Endace 2016 | Public Distribution Permitted

Investigations Leveraging Network History The network is the key • • •

All activity takes place on the network – but networks have no memory Recording packet-level history provides definitive evidence of what’s happened A fabric of network recorders can provide network-wide history

Give all your tools access to Network History • • •

Endace Fusion APIs provide powerful workflow integration Commercial, open-source and custom applications Shrink-wrapped connectors for Fusion Partner apps

Deep, back-in-time historical analysis •

Page 3

Playback Network History for offline historical analysis and investigation

© Endace 2016 | Public Distribution Permitted

EndaceProbe Network Recorders 100% accurate recording, 10Mbps to 100Gbps • Open platform – API for streamlined workflow with partner apps – AFV hosting of virtualized analytics applications

• Days to months of network history storage Flexible and scalable fabric • Centralized recall and investigation • Centralized management, ultra-scalability Built-in investigation tools • EndaceVisionTM and EndacePacketsTM Page 4

© Endace 2016 | Public Distribution Permitted

Built-in investigation tools EndaceVision • Browser-based GUI tool for searching and visualizing Network History • Zoom in and out to look at pre-cursor or post-event traffic • Identify packets of interest for analysis EndacePackets • Browser-based packet decode tool based on WiresharkTM • Analyze packets directly on the EndaceProbe

Page 5

© Endace 2016 | Public Distribution Permitted

Workflow Integration using Fusion APIs Powerful REST APIs for streamlining workflows Pivot to Packets •

Pivot directly from an alert in a 3rd-party app (like DC RUM) to relevant packets for analysis

Pivot to Vision • •

Page 6

Pivot from a 3rd-party app directly to a visualization of related network history Can go directly from a visualization to EndacePackets

© Endace 2016 | Public Distribution Permitted

Host 3rd-Party Analytics Applications Host Applications in Application DockTM on EndaceProbes • Quickly deploy analytics across EndaceProbe estate using centralized orchestration • Hosted applications have full access to real-time traffic and recorded Network History Playback Network History to hosted applications • Slowly for deep analysis • Quickly for fast, targeted investigations Host Dynatrace’s virtual AMD in Application Dock

Page 7

© Endace 2016 | Public Distribution Permitted

Dynatrace DC RUM Workflow Example

1

Page 8

© Endace 2016 | Public Distribution Permitted

Looking at Application Response issues in CAS Console

Dynatrace DC RUM Workflow Example

2

Page 9

© Endace 2016 | Public Distribution Permitted

Click on user to retrieve related packets from EndaceProbe history

Dynatrace DC RUM Workflow Example

3

Page 10

© Endace 2016 | Public Distribution Permitted

Search parameters are pre-filled

Dynatrace DC RUM Workflow Example

4

Page 11

© Endace 2016 | Public Distribution Permitted

Packets are retrieved for analysis in Wireshark or other packet decode tools such as DNA