PI IP Flow Interface
From SCADApedia
General
Routers and switches from many vendors provide NetFlow, sFlow or IPFIX data. This data is sent to a collection point where and administrator can view information about the network. The following information is typically collected: Source Address, Source Port, Source MAC, Destination Address, Destination Port, Destination MAC, IP Protocol, Number of bytes.
The flow data can then be sent to a PI IP Flow interface. The IP Flow interface then sends the data to the PI server for analysis.
Impact
In the PCS arena, analysis of data from the IP Flow interface can show trends in the amount of traffic on the network, new systems on the network and unusual network behavior. The information can be used to determine if an attacker is scanning the network or if the PLCs are generating more traffic because there is a problem on a device.
